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Abstract 



Can a classical system command a general adversarial quantum system to realize 
arbitrary quantum dynamics? If so, then we could realize the dream of device-independent 
quantum cryptography: using untrusted quantum devices to establish a shared random 
key, with security based on the correctness of quantum mechanics. It would also allow 
for testing whether a claimed quantum computer is truly quantum. Here we report a 
technique by which a classical system can certify the joint, entangled state of a bipartite 
quantum system, as well as command the application of specific operators on each 
subsystem. This is accomplished by showing a strong converse to Tsirelson's optimality 
result for the Clauser-Horne-Shimony-Holt (CHSH) game: the only way to win many 
games is if the bipartite state is close to the tensor product of EPR states, and the 
measurements are the optimal CHSH measurements on successive qubits. This leads 
directly to a scheme for device-independent quantum key distribution. Control over the 
state and operators can also be leveraged to create more elaborate protocols for realizing 
general quantum circuits, and to establish that QMIP = MIP*. 
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1 Introduction 



Do the laws of quantum mechanics place any limits on how well a classical experimentalist can 
characterize the state and dynamics of a large quantum system? As a thought experiment, consider 
that we are presented with a quantum system, together with instructions on how to control its 
evolution from a claimed initial state. We make no assumptions about its inner structure, aside 
from its conforming to quantum mechanics. Can we, as classical beings, possibly convince ourselves 
that the quantum system was indeed initialized as claimed, and that its state evolves as we instruct? 

More formally, model the quantum system as contained in a black box, and model our classical 
interactions with it as questions and answers across a digital interface, perhaps of buttons and light 
bulbs (Figure 1). Using this limited interface, we wish to characterize the initial state of the system. 
We also wish to certify that on command — by pressing a suitable sequence of buttons — the system 
applies a chosen local Hamiltonian, or equivalently a sequence of one- and two-qubit quantum gates, 
and outputs desired measurement results. 

Although partly a philosophical question, a positive resolution would have important conse- 
quences. It is particularly relevant in quantum cryptography, where it is natural to model the 
quantum system as adversarial since the goal is to protect honest users from malicious adver- 
saries. Public- key distribution schemes have security based on the assumed difficulty of solving 
certain problems [DH76, RSA78], but quantum algorithms can violate these assumptions [Sho97]. 
The raison d'etre of quantum cryptography is to create a cryptographic system with security 
premised solely on basic laws of physics, and with quantum key distribution (QKD) and its security 
proofs [BB84, LC99, SPOO] it appeared to have achieved exactly this. However, attackers have 
repeatedly breached the security of QKD experiments, by exploiting imperfect implementations of 
the quantum devices [ZFQ+08, LWW + 10, GLL+11]. Rather than relying on ad hoc countermea- 
sures, Mayers and Yao's 1998 vision of device-independent (DI) QKD [MY98], hinted at earlier by 
Ekert [Eke91], relaxes all modeling assumptions on the devices, and even allows for them to have 
been constructed by an adversary. It instead imagines giving the devices tests that cannot be passed 
unless they carry out the QKD protocol securely. The challenge at the heart of this vision is for a 
classical experimentalist to force untrusted quantum devices to act according to certain specifications. 
DIQKD has not been known to be possible; security proofs to date require the unrealistic assumption 
that the devices have no memory between trials, or that each party has many, strictly isolated 



Figure 1: Classical interaction with a quantum system. A general system can be abstracted 
as a black box, with two buttons for accepting binary input and two light bulbs for output. Using 
this interface, we wish to control fully the system's quantum dynamics. 
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devices [BHK05, MRC+06, AMP06, Mas09, HRW10, ABG+07, PAB+09, McK09, HRIO, MPA11]. 1 
A scheme for characterizing and commanding a black-box quantum device would provide a novel 
approach to achieving DIQKD. 

Further, as the power of quantum mechanics is harnessed at larger scales, for example with 
the advent of quantum computers, it will be useful to evaluate whether a quantum device in fact 
carries out the claimed dynamics [ABE10, BFK09]. Finally, we might wish to test the applicability 
of quantum mechanics for large systems, a situation in which Nature itself plays the role of the 
adversary [AVI 2]. 

The existence of a general scheme for commanding an unmodeled quantum device appears 
singularly implausible. For example, in an adversarial setting, experiments cannot be repeated exactly 
to gather statistics, since a system with memory could deliberately deceive the experimentalist. 
More fundamentally, as macroscopic, classical entities, our access to a quantum system is extremely 
limited and indirect, and the measurements we apply collapse the quantum state. We have never 
experienced quantum superposition — and likely nor have our cats. Furthermore, whereas the 
dimension of the underlying Hilbert space scales exponentially in the number of particles or can be 
infinite, the information accessible via measurement only grows linearly. Indeed, as formulated it is 
impossible to command a single black-box system. Quite simply, one cannot distinguish between a 
quantum system that evolves as desired and a device that merely simulates the desired evolution 
using a classical computer. 

In this paper, we consider a closely related scenario. Suppose we are instead given two devices, 
each modeled as a black box as above, and prevented from communicating with each other. In this 
setting, with no further assumptions, we show how to classically command the devices. That is, 
there is a strategy for pushing the buttons such that the answering light bulb flashes will satisfy 
a prescribed test only if the two devices started in a particular initial quantum state, to which 
they applied a desired sequence of quantum gates. Moreover, though impractical, the scheme 
is theoretically efficient — in the sense that the total effort, measured by the number of button 
pushes, scales as a polynomial function of the size of the desired quantum circuit. Among other 
consequences, this result is still sufficiently powerful to imply a DIQKD scheme. The necessary 
security assumptions are minimal: that the parties have isolated laboratories (as cryptography 
requires secrecy), they have local sources of random bits and share an authenticated classical 
communications channel (to prevent man-in-the-middle attacks), and quantum theory is correct. 

The starting point for our protocol is the famous Bell experiment [Bel64] , and its subsequent 
distillation by Clauser, Home, Shimony and Holt (CHSH) [CHSH69]. Conceptually modeled as a 
game (Figure 2), it provides a "test for quantumness," a way for a classical experimentalist, whom 
we shall call Eve, to demonstrate the entanglement of two space-like separated devices, Alice and 
Bob. Eve bases her decision, "quantum" or "not quantum," according to whether her interactions 
with the two devices satisfy non-local correlations, which are provably impossible to achieve in 
any local hidden variable theory. Quantum devices can achieve such correlations, without any 
communication, by measuring two entangled qubits. 

Consider a protocol in which Eve plays a long sequence of CHSH games with Alice and Bob, 
and tests that they win close to the optimal fraction u* of the games. This paper's main technical 
result establishes that if the devices pass Eve's test with high probability, then at the beginning of a 
randomly chosen long subsequence of games, Alice and Bob must share many EPR states in tensor 

^^Refs. [HRIO, MPA11] assume only that measurements for different games commute. This is mathematically 
weaker than requiring measurements to lie in tensor product, but places the same constraints on an implementation. 
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Figure 2: Test for quantumness. In a CHSH experiment, or "game," the experimentalist Eve 
sends independent, uniformly random bits A and B to the devices Alice and Bob, respectively, who 
respond with bits X and Y . The devices "win" the game if AB — X © Y. By a Bell inequality, 
classical devices can win with probability at most 3/4. The probability of two classical devices winning 
(3/4 + e)n out of n games is therefore exponentially small. Quantum devices can win the CHSH 
game with probability up to oj* = cos 2 (|) « 85.4%, by Tsirelson's inequality [Tsi80], if they follow 
an ideal CHSH strategy: on a shared Einstein-Podolsky- Rosen (EPR) state \cp) = -^(|00) + |11)), 

Alice measures the Pauli operator a z if A = or a x if A = 1, and Bob measures -^{&z + ( — 1) B &x)- 



product, that they measure one at a time using the single-game ideal CHSH operators of Figure 2. 
This is a step towards the general vision outlined above because it characterizes the initial state of 
many qubits, and allows Eve to command the devices to perform certain single-qubit operations. 
Of course, we cannot hope to characterize the devices' strategies exactly, but only for a suitable 
notion of approximation. 

In order to make a more precise statement, first consider a single CHSH game. We show that if 
Alice and Bob win with probability cj* — e, then they must share a state that is 0(v / ^)-close to an 
EPR state, possibly in tensor product with an additional state. Moreover their joint measurement 
strategy is necessarily 0(yJe)-c\ose to the ideal strategy. (That is, applying Alice's measurement 
operator to the shared state gets within distance 0(y/e) of her ideal measurement operator applied 
to the EPR state tensored with the ancilla; and similarly for Bob.) Since each device can store 
its share of the EPR state in an arbitrary way, e.g., as a logical qubit spread over several physical 
qubits, these statements hold only up to local isometries. This may be seen as a robust converse 
to Tsirelson's inequality, and as a rigidity property of the CHSH game: a nearly maximal Bell 
inequality violation rigidly locks into place the devices' shared state and measurement directions. 

A converse to Tsirelson's inequality for the CHSH game has been shown previously in the 
exact case [BMR92, PR92]. Robustness is important for applications, however, because the success 
probability of a system can never be known exactly. Robust, e > 0, converse statements have 
been shown based on a conjecture [BLM+09] or under restrictive symmetry assumptions [ABG + 07, 
PAB+09]. 2 Recently, robustness has independently been shown for the CHSH game [MYS12, MS12]. 

Scaling up to a sequence of n CHSH games, suppose Alice and Bob use a strategy such that they 
win at least (1 — e)cj*n of the games with high probability. By basic statistics, their strategy at the 
beginning of most games will win with probability at least (1 — e^ 1 ))^*. Rigidity for the one-shot 
game therefore applies. However, their strategy for playing the jth game could depend on the 
previous games. The states close to EPR states used in different games could overlap significantly, 
and their locations could depend on the history. The multi-game rigidity theorem rules out such 

2 Similar e = statements have been shown for other games [MY04, MY98, CK11, Col06], and Magniez et 
al. [MMMO06] have shown that the game in [MY98] is 0(e 1/4 )-robust to error e > 0. 
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wayward behavior. It says that for most random blocks of m = consecutive games, at the start 

of the block Alice and Bob must share a state that is close to a tensor product of m EPR states, 
tensored with an additional state, and must play each jth game by making measurements that are 
close to the ideal CHSH strategy on the jth EPR state — different games being entirely independent. 

One way to view this theorem is that it scales up the CHSH test for quantumness and allows for 
identifying many qubits' worth of entanglement. Much more than that, however, the multi-game 
rigidity theorem gives strong control over the devices' measurement operators for different games. 
Combined with protocols for state and process tomography, and for computation by teleportation, 
this gives a method for realizing arbitrary dynamics in quantum systems without making assumptions 
about the internal structure or operations. The dynamics are realized as the joint evolution of 
two isolated quantum systems, Alice and Bob, mediated by a classical experimentalist, Eve. In 
order to realize the desired dynamics, Eve starts by testing the systems (devices) by playing with 
them many sequential CHSH games. She gathers statistics and rejects if they lose too many games; 
by rigidity, this forces them to play nearly honestly. At the beginning of a random block of m 
games, Eve stops playing with Alice but continues on with Bob. Bob cannot tell that anything has 
changed, so continues playing the same way, measuring his halves of the EPR states. Eve directs 
Alice to apply more complicated, multi-qubit operations, and she uses Bob's measurement results to 
tomographically certify Alice's compliance. In a symmetrical manner, Eve can force Bob to follow 
her directions. Finally, with a certain probability, Eve stops both Alice and Bob before the same 
block of m games, and she directs them both to apply multi-qubit operations on the next m EPR 
states. The desired dynamics are implemented a step at a time, with the working qubits teleported 
back and forth between the two parties. This zig-zagging evolution is natural because it allows 
complicated evolutions to be built out of simple, few-qubit operations; direct tomography on a 
many-qubit operation would be extremely inefficient. Ultimately, should she wish, Eve can direct a 
full-scale quantum computation (Figure 3). 

The problem of controlling computationally powerful but untrusted resources lies at the founda- 
tion of computer science. In the complexity class NP, for example, a polynomial-time routine — the 
"verifier" — is allowed one round of interaction with an arbitrarily powerful, but malicious, "prover." 
We show that the same verifier can exploit the power of quantum-mechanical provers. In particular: 

1. A classical verifier can efficiently simulate a quantum computer by interacting with two 
untrusted, polynomial-time quantum provers. This delegated computation scheme is also 
blind, meaning that each prover learns no more than the length of the computation. 

2. The verifier in any quantum multi-prover interactive proof (QMIP) system can be assumed 
to be classical. Formally, the complexity classes QMIP and MIP* are equal, where MIP* is 
the class of languages decidable by a classical interactive protocol in which the provers share 
entanglement. 

Previous work has considered a verifier who can store and control a constant number of qubits 
while interacting with a single prover [ABE10, BFK09, FK12, BKB+12]. This makes controlling 
the system easier; for example, in the simplest scheme, the prover acts as an authenticated quantum 
memory and all computation is done by the verifier. Our work is also inspired by a proposal [BFK10] 
that QMIP should equal MIP*. The protocol introduced there can be attacked, however. Our 
protocol has a very different form, based on the multi-game rigidity theorem. 

Thus a classical experimentalist can control quantum devices even under the weakest possible 
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Figure 3: Sub-protocols for verified quantum dynamics, a, Say that Eve wants to delegate to 
Alice and Bob a quantum circuit C, over the gate set {H, G, CNOT}, where H is the Hadamard gate 
and G a 7r/4 rotation about the y axis, b, The idea is to use computation by teleportation [GC99], 
which allows a gate, here H, to be implemented by a two-qubit Bell measurement on the input and 
half of a resource state, (/ ® H)\cp). Eve runs a random one of four sub-protocols with Alice and 
Bob. c, Playing many CHSH games ensures that the devices play honestly using shared EPR states, 
d-e, This lets Eve apply state or process tomography to characterize more complicated multi-qubit 
operations, f, By adaptively combining these operations, Eve directs the circuit C. The zig-zagging 
logical path of the first qubit of C is highlighted. 
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assumptions, in which the devices are not just imprecise or noisy, but are maliciously adversarial, 
and arbitrarily crafty. 

2 Proof sketches 

In this section, we sketch the main proofs, especially the characterization of strategies for sequential 
CHSH games. The notation is presented intuitively, but of course precise definitions are given later. 

2.1 Rigidity of the CHSH game 

The proof of the single-game rigidity theorem (Lemma 4.2) is a good place to start. We show 
that nearly saturating Tsirelson's inequality nearly determines the devices' joint strategy. To win 
the CHSH game with probability u* — e, the devices' strategy must, up to local basis changes, be 
0(y / e)-close to the ideal strategy of Figure 2, involving measurements on two halves of an EPR 
state. 

A general strategy for Alice and Bob consists of some shared mixed state in T-La ®7~Lb, and two- 
outcome projective measurements for each of Eve's possible questions. Truncate the devices' Hilbert 
spaces to finitely many dimensions, then decompose each space by Jordan's Lemma (Lemma 4.3) 
into the direct sum of two-dimensional spaces invariant under the projections. The probability of 
winning is a convex combination of the success probabilities of the strategies that restrict the shared 
state to a two-dimensional space on each device's side, C 2 ® C 2 . Therefore it suffices to analyze the 
two-dimensional case, which we do by adjusting the angles between the projections to match the 
ideal strategy. The resulting operators define the underlying qubits. 

2.2 Tensor-product structure for repeated CHSH games 

A strategy S for playing n sequential CHSH games specifies Alice and Bob's initial joint state as 
well as their measurement operators for every possible situation. That is, for X E {^4, B} and each 
j = 1, . . . , n, S specifies the measurement operators used by device X in game (j, h^ ) _ 1 ) 1 where h^_ x 
is any transcript of the device's input and output bits for the first j — 1 games. For two strategies 
to be "close" means that the distributions of game transcripts they induce should be close in total 
variation distance; and that for most transcripts (drawn from either distribution), the resulting 
quantum states should be close in a suitable norm. We combine these conditions into one by defining 
for any strategy a block-diagonal density matrix that stores both the classical transcript and the 
resulting quantum state: 

Pj = ®^[hj-i]Pj{hj-i) ■ (2-1) 

hj-! 

Here hj-i = (h^_ v h?_ ± ) is the full transcript for the first j — 1 games and pj{hj-\) is the state at 
the beginning of game j conditioned on hj-\. Two strategies S and S are close if the associated pj 
and pj are close in trace distance, for every j. 

Assume that for every j and most hj-i, the devices' conditional joint strategy at the beginning 
of game j is "e-structured," meaning that it wins with probability at least cj* — e. Our key theorem 
establishes that up to local basis changes, the devices' initial state must be close to n EPR states, 
possibly in tensor product with an irrelevant extra state, and that their total strategy S must 
be close to an ideal strategy S that plays game j using the jth EPR state. Since the structure 
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assumption can be established by martingale arguments on poly(n) sequential CHSH games, this 
implies the multi-game rigidity theorem. See Theorems 5.7 and 5.39 for precise statements. 

2.2.1 Construction of the ideal strategy S 

The main challenge is to "locate" the ideal strategy S within Alice and Bob's Hilbert space, i.e., to 
find an isometry on each of their spaces under which their states and measurement operators are 
close to ideal. However, a priori, we do not know whether S calls for the devices to measure actual 
qubits in each step, or even if so whether the qubits form EPR states, qubits for different games 
overlap each other, or the locations of the qubits depend on the outcomes of previous games. 

The given strategy S can be transformed into a nearby ideal strategy 5 by a three-step sequence: 

1. First, replace each device's measurement operators by the ideal operators promised by the 
single-game rigidity theorem. In the resulting strategy <S, each device X plays every game (j, 
using the ideal CHSH game operators on some qubit, up to a local change in basis. However, the 
basis change can depend arbitrarily on h^_ Xl and the qubits for different j need not be in tensor 
product. 

2. In a "multi-qubit ideal strategy" <S, the qubits used in each game can still depend on the 
local transcripts but must at least lie in tensor product with the qubits from previous games. This 
imposes a tensor-product subsystem structure that previous DIQKD proofs have assumed. The 
tensor-product structure is constructed beginning with a trivial transformation on S: to each device, 
add n ancilla qubits each in state |0). Next, after a qubit has been measured, say as \aj) in game j, 
swap it with the jth ancilla qubit, then rotate this fresh qubit from |0) to |ay) and continue playing 
games j + 1, . . . , n. This defines a unitary change of basis that places the outcomes for games 1 
to j in the first j ancilla qubits, and leaves the state in the original Hilbert space unchanged. Since 
qubits are set aside after being measured, the qubits for later games are automatically in tensor 
product with those for earlier games; the resulting strategy S is multi-qubit ideal. At the end of the 
n games, swap back the ancilla qubits and undo their rotations, using the transcript. 

3. In the last step, we replace S with an ideal strategy <S, in which Alice and Bob each play using 
a fixed set of n qubits. Fix a transcript h ni chosen at random from the distribution of transcripts 
for S. For the first time, change the devices' initial state: replace pi with pi, a state having n 
EPR states in the locations determined by h n in S. In <S, the devices play using these EPR states, 
regardless of the actual transcript. This S is the desired ideal strategy. 

2.2.2 Ideal strategy S is close to S 

It remains to show that the transformation's three steps incur a small error: S is close to S. A 
major theme in the analysis is to leverage the known tensor-product structure between %a and T~Lb 
to extract a tensor-product structure within Ha and %b- The steps are illustrated schematically in 
Figure 4. 

1. S ~ S: Although elementary, explaining this step is useful for establishing some notation. 
Let pi be the devices' initial shared state, possibly entangled with the environment. Let £^ 
and £ B be the super-operators that implement Alice and Bob's respective strategies for game j, 
8f B = Sf ® £f and £f B = £^ B • • • £f B for j < fc; thus the state Pj of Eq. (2.1) equals Sff^pi). 
For D E {A,B}, let be the super-operator that replaces the actual measurement operators with 
the ideal operators promised by the CHSH rigidity theorem. S is given by pi, {£f} and {£f}- If 
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(a) General strategy (b)Single-qubit ideal strategy (c)Multi-qubit ideal strategy (d) Ideal strategy 



Figure 4: Proof outline for the multi-game rigidity theorem, a, Initially, each device D E {^4, B} can 
play arbitrarily, measuring in game j one of two reflections that depend on the local transcript h^_ x 
for the previous games. No structure is given for the Hilbert space %d- b, We first show that 
D's strategy is close to a "single-qubit ideal strategy," in which for every game it measures some 
qubit using the ideal CHSH game strategy, but the qubit locations can be arbitrary. Here, the 
qubits are illustrated as balls, and the overlaps indicate that they need not be in tensor product, 
c, We then construct a nearby "multi-qubit ideal strategy," in which the qubits used in each game 
must lie in tensor product with the qubits from previous games, but can overlap qubits used along 
other transcripts, d, Finally, we argue that the qubit locations cannot depend significantly on the 
transcript, and therefore that the original strategy is well- approximated by an ideal strategy that 
measures a fixed set of n qubits in sequence. (Note that these visualizations, representing qubits as 
balls, are inherently imprecise. A qubit 's location in a Hilbert space is given not by a ball, but by 
the two anti-commuting reflection operators a x and a z .) 

Prfgame j is e-structured] > 1 — 5, then \\£f B (pj) — £f B (Pj)\\tr < 25 + O(^fe). (This expression 
uses Eq. (2.1) to combine bounds on the probability of the bad event and the 0{^fe) error from the 
good event.) To show our goal, that £\ B {pi) ~ £\n(p^) m trace distance, use a hybrid argument 
that works backwards from game n to game 1 fixing each game's measurement operators one at 
a time. The error introduced from fixing a game j, by moving from £^ B (pj) to £f B (pj), does 
not increase in later games because applying a super-operator cannot increase the trace distance. 
Mathematically, this hybrid argument is simply a triangle inequality using the expansion 

2. S « S: The key to showing that S is close to S is the fact that operations on one half 
of an EPR state can equivalently be performed on the other half, since for any 2x2 matrix M, 
(M®J)(|00) + |11)) = (7®M T )(|00) + |11)). This means that the outcome of an e-structured CHSH 
game would be nearly unchanged if Bob were hypothetically to perform Alice's measurement before 
his own. By moving Alice's measurement operators for games j + 1 to n over to Bob's side, we see 
that they cannot significantly affect the qubit \aj) from game j on her side. Therefore, undoing the 
original change of basis restores the ancilla qubits nearly to their initial state |0 n ), and S ~ S. 

Formally, define a unitary super-operator Vj that rotates the jth ancilla qubit to |ay), depending 
on Alice's local transcript h^. Define a unitary super-operator Tj to apply Vj and swap the jth 
ancilla qubit with the qubit Alice uses in game j (depending on h^_ r ). Alice's multi-qubit ideal 
strategy is given by 

Sf = 7i~- 1 _ 1 (l C 2» ® £f)Ti d -i . (2.2) 
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We aim to show that the strategy given by pi, {£f} and {£f} is close to <S up to the fixed isometry 
that prepends |0 n )(0 n | to the state. Define a super-operator T^ B , in which Alice's measurements 
are made on Bob's Hilbert space %Bi on the qubit determined by Bob's local transcript h?_ v Since 
most games are e-structured, by the CHSH rigidity theorem, k (pj+i) « &f+i fc(Pj+i) = Pk+i 
for any j < k. Since k acts on %b, it does not affect Alice's qubit \aj) from game j at all, 
and so this qubit must stay near \aj) in pk+i as well, i.e., the trace of the reduced density matrix 
against the projection \aj)(aj\ stays close to one. As this holds for every j, T{~^ indeed returns the 
ancillas almost to their initial state |0 n ). 

In more detail, let Xj be the operator that projects onto Alice's jth ancilla qubit and the 
qubit she uses in the jth game being |0) ® \aj). By definition, Tr(Xj pj+i) = 1. By the Gentle 
Measurement Lemma (Lemma 3.4), it suffices to show that Tr(Xj pk+i) — Tr Xj£j^ k (pj+i) « 1. 
This is not obvious; since the operators for games j + 1 to k do not act in tensor product, they can 
disturb the qubit measured in game j. However, since a super-operator on cannot affect the 
expectation of an operator supported on %Ai we find 

Tv(X 3 p k+1 ) = TrX 3 £f^ k (p 3+1 ) * Tr X 3 jft B 1(fc (p;+i) = Tr(X 3 p j+1 ) = 1 . 

The {£f} are symmetrically adjusted to {£f}- 

3. 5^5: Intuitively, if the location of Alice's jth qubit depended on h^_^ then without any 
communication Bob could not know which of his qubits to measure. However, Alice and Bob's 
transcripts are significantly correlated, and we must show that they cannot use these correlations to 
coordinate the locations of their qubits. 

We argue that S closely approximates <S, provided that h n satisfies: for every j, conditioned on 
the partial transcript hj-i, (a) game j is e-structured, and (b) there is a high probability that every 
subsequent game is e-structured. By Markov inequalities, most transcripts satisfy these conditions. 

We connect S to S by an argument that one game at a time switches play to locate qubits 
according to h n . The intermediate steps relate strategies in which the devices locate their qubits 
using a hybrid (hj, hj+i^ n ) of h n and the actual transcript h n . 

Consider a partial transcript hj that differs from hj only in the jth game, say on Alice's side. 
By (a) and the CHSH rigidity theorem, Alice's jth qubit is collapsed and nearly in tensor product 
with the rest of the state. Therefore, there exists a unitary V^ 4 acting on this qubit such that 

p j+1 {h 3 )^V 3 A p 3+1 {h 3 )V^ , (2.3) 

up to error 0(y/e). Since applying a super-operator cannot increase trace distance and on Bob's 
side h? = hf ', therefore 

- AB\h B 

Here, J r - +1 ^ is the same super-operator used in the multi-qubit ideal strategy simulation step — that 
plays Alice's games on Bob's qubits — except conditioned on the local transcript . By condition 
(b), these super-operators can be pulled back to Alice's side, to give 

(Pi + i(hj)) ~V 3 A £f^{p 3+1 {h 3 ))vV . 

Note that this approximation does not follow immediately from Eq. (2.3), because Alice's super- 
operators conditioned on can be very different from her super-operators conditioned on h^. 
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By fixing the coordinates one at a time in this way, we find that for a typical transcript h ni 
Pn+i(hn) ~ y^nPn+iih n )V^\ and we conclude that £$(pi) « £^n(pi)- 

Since measures qubits in tensor product with each other, by using the CHSH rigidity theorem 
one last time, it is not difficult to show that £\n{pi) ~ ^uf wnere Pi nas n EPR states in the 
qubit positions determined by h n . Thus the devices' actual strategy S = (pi, {£f}, {£f}) ls dose 
to the ideal strategy S — (pi, {£f}, {£f}), as desired. 

The conclusion that the devices' joint strategy is close to ideal is not strong enough for our 
applications, in which sometimes Eve plays CHSH games with only one of the two devices. We need 
to show that the devices' strategies are separately close to ideal, i.e., 

^n(Pi) « A A n(Pi) and S* n ( Pl ) « S^JM . (2.4) 

These estimates cannot be obtained directly because our main assumption, that every game j is 
usually e-structured, is only of use if both devices have played games 1 through j — 1 — it gives 
information about £® applied to £f^_ 1 (pi), not about £® applied to fj D J _ 1 (pi). The key idea to 
obtain separate estimates is that applying both devices' super-operators is almost equivalent to 
applying Alice's super-operator, guessing Bob's measurement outcome from the ideal conditional 
distribution, and based on the guess applying a controlled unitary correction to his qubit. Since 
Alice's super-operator collapses both qubits of the EPR state, it is not actually necessary to measure 
Bob's qubit. Defining Q? to be this guess-and-correct super-operator, two hybrid arguments give 

*iJ?(Pi) « ^d E&ZM « 9?JiM. Thus, 

The same super-operator Qf n appears on both the left- and right-hand sides above. In general, 
applying a super-operator can reduce the trace distance. In this case, however, it does not; the 
correction part of Qf n is unitary, and the guessing part is a stochastic map acting on a copy of 
Alice's classical transcript register. Therefore, indeed £\ n (pi) ~ £f n (pi). The third step of the 
proof uses a similar, but more involved, argument. 

2.3 Verified quantum dynamics 

Our scheme for verified quantum dynamics is based on the idea of computation by teleporta- 
tion [GC99]. Say that Eve wants to simulate a quantum circuit C, over the gate set {H, G, CNOT}, 
where H is the Hadamard gate and G = exp(— is a 7r/4 rotation about the y axis of the Bloch 
sphere. Eve asks Bob to prepare many copies of the resource state |0) ® (/ ® H)\ip) ® (/ ® G)\cp) ® 
CNOT2,4(|(p) |<p)). He can do so by applying one-, two- and four-qubit measurements to his halves 
of the shared EPR states and reporting the results to Eve. If he plays honestly, Alice's shares of the 
EPR states collapse into the desired resource states, up to simple corrections. Each resource state 
corresponds to a basic operation in C. Eve wires these up by repeatedly directing Alice to make a 
Bell measurement connecting the output of one operation to the input of the next operation in C. 
After each G gate, an H correction might be required. 

Of course, Alice and Bob might not follow directions. To enforce honest play, Eve runs this 
protocol only a small fraction of the time, and otherwise chooses uniformly between three alternative 
protocols sketched in Figure 3. Let m = |C| 0( ^ and n = mP^. 
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1. In the "state tomography" protocol, Eve chooses K uniformly from {1, . . . , n/m}. She referees 
(K — l)m CHSH games with both devices. Then in the Kth block of m, Eve asks Bob to 
prepare the resource states, in a random order, while continuing to play CHSH games with 
Alice. Eve rejects if the tomography statistics are inconsistent. We prove that if Alice plays 
honestly and Eve accepts with high probability, then on most randomly chosen small subsets 
of the resource state positions, Alice's reduced state is close to the correct tensor product of 
resource states. 

2. In the "process tomography" protocol, Eve again chooses K uniformly from {1, . . . , n/m} 
and referees (K — l)m CHSH games. In the Kth block of m, Eve asks Alice to make Bell 
measurements on random pairs of qubits, while continuing to play CHSH games with Bob. If 
Alice's reported result for any pair of qubits is inconsistent with Bob's outcomes, Eve rejects. 
Then if Bob plays honestly and Eve accepts with high probability, Alice must also have applied 
the Bell measurements honestly. 

3. In the third protocol, Eve simply referees n sequential CHSH games with both devices and 
rejects if they do not win at least (1 — e)cj*n games. 

From Bob's perspective the process tomography and computation protocols are indistinguishable, 
as are the state tomography and CHSH game protocols. From Alice's perspective, the state 
tomography and computation protocols are indistinguishable, as are the process tomography and 
CHSH game protocols. The devices must behave identically in indistinguishable protocols. The 
multi-game rigidity theorem therefore provides the base for a chain of implications that implies that 
if Eve accepts with high probability, then the devices must implement C honestly. 

Four main technical problems obstruct these claims. 

First, in the state tomography protocol, if Bob is dishonest, then Alice gets an arbitrary m- 
qubit state, and there is no reason why it should split into a tensor product of const ant-qubit 
states. Standard state tomography and certification arguments require many copies of a state and 
so do not apply. Nonetheless, we argue using martingales that if the counts of Alice's different 
measurement outcomes roughly match their expectations with high probability, then for most 
reported measurement outcomes from Bob and for most subsystems j, Alice's conditional state 
reduced to her jth subsystem is close to what it should be. 

Furthermore, saturating Tsirelson's inequality for the CHSH game only implies that Alice 
is honestly making Pauli a x and a z measurements on her half of an EPR state. Tomography 
also requires a y measurements. To sidestep this issue, we generalize a theory introduced by 
McKague [McKlO] and prove that there is a large class of states, including the necessary resource 
states, that are all robustly determined by only a x and a z measurements. 

A bigger problem, though, is that we want to characterize the operations that the devices apply 
to their shared EPR states, and not just the states that these operations create on the other side. 
The distinction is the same as that between process and state tomography. Essentially, the problem 
is that the correct states could be generated by incorrect processes. Moreover, as for sequential 
CHSH games, Bob's strategy in early tomography rounds might be sufficiently dishonest as to allow 
him in later rounds to apply completely dishonest operators. For example, Bob could cheat in the 
first requested round by cyclically shifting all of his EPR state halves. A statistical test will not 
suffice to detect one round of cheating. However, if after this first round he plays using the shifted 
ideal operators, his operations will all be completely dishonest even though they have the correct 
effect on Alice's side. 
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A key observation to avoid this problem is that it is enough to certify the states prepared by one 
device and the processes applied by the other. Then since a broad class of states can be certified, for 
applications it suffices to certify a much smaller set of operations. We restrict consideration to Pauli 
stabilizer measurements [Got97]. For Pauli operators in the stabilizer of a state, the measurement 
outcome is deterministic. Therefore if Alice reports the wrong stabilizer syndrome in even a single 
round, Eve can reject. Our process certification analysis is similar to some of the arguments used 
above. We argue that Alice's earlier measurements cannot usually overly disturb the qubits intended 
for use in later measurements, by pulling Alice's measurement super-operators over onto Bob's 
halves of the EPR states. 

Finally, the verifier's questions in the state and process tomography protocols are non-adaptive, 
whereas in computation by teleportation the questions must be chosen adaptively based on previous 
responses. This is an attack vector in some related protocols. However, we argue that the devices 
can learn nothing from the adaptive questions. 

More formally, let p be the initial state, and let B be the super-operator describing Eve's 
interactions with Bob in state tomography. Roughly, state tomography implies that the states Bob 
prepares on Alice's side are correct up to a small error in trace distance, or 

Tr B B(p)*Tr B B(p) , (2.5) 

where B is the ideal super-operator and p is an ideal initial state consisting of perfect EPR 
states. Similarly, let A be the super-operator describing Eve's interactions with Alice in a process 
tomography protocol on Alice's operations; we have 

A(p) « A(p) . (2.6) 

Computation by teleportation can be implemented either by choosing Bob's state preparation 
questions non-adaptively and Alice's process questions adaptively, or vice versa. We show that these 
are exactly equivalent regardless of the devices' strategies, i.e., 

AaB = B^A , (2.7) 

where A&& and £> a d are the same as A and £>, respectively, except with Eve choosing her questions 
adaptively based on the previous messages. Combining these steps, we therefore obtain 

TtbB^A(p) ~ Tr B B ad A(p) 
= Ad Tr# B{p) 
~ AdTr B a d(/3) , 

and thus the actual computation by teleportation protocol leaves on Alice's side nearly the ideal 
output. 

The proof that QMIP = MIP* follows along similar lines. Begin with a fc-prover protocol. We 
may assume that it has two rounds of quantum messages from the provers, before and after the 
verifier broadcasts a random bit [KKMV09]. To convert to an MIP* protocol, with classical messages, 
add two additional provers, Alice and Bob. Eve teleports the original k provers' messages to Alice, 
and directs Alice and Bob together to apply the quantum verifier's acceptance predicate. 
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3 Background and notation 



For a natural number n, let [n] = {1,2,..., n}. Let S n be the symmetric group of degree n. Let S a ^ 
be the Kronecker delta function. The Pauli operators are tensor products of the matrices I — (J ?)? 
X = (5o) 5 ^=(?V) an< ^ ^ = ( J -i ) • The latter three matrices were earlier termed a Xl a yi a z . 
Let iJ = (} j^), the Hadamard gate, and G = exp(— i^Y) = J^V 8 )■ 

The complex and real numbers are denoted by C and R, respectively. For a finite set £, let C s 
be the complex Hilbert space C^l with orthonormal basis {\x) : x E S}. We assume familiarity 
with ket notation, e.g., J2 x eS \ x )( x \ = 1> the identity on C^. For vector spaces V and over C, 
let £(V, W) denote the set of all linear transformations from V into W, and let £(V) = £(V, V). 
For an operator A, denote by ||A|| its spectral norm, and by ||^4||tr its trace norm, i.e., the sum of 
its singular values. 

We assume familiarity with the basics of quantum computation as found, e.g., in [NCOO]. In 
particular, for a Hilbert space a (mixed) state is a positive semi-definite operator p E with 
trace one, and a pure state is a rank-one state. The evolution of a quantum system is described by 
a super-operator £, a map from states on % to states on T-C which can in general be specified by a 
set {E k } C C{U,W) of "Kraus operators" satisfying Y,k E l E k = £(p) = Y,k E kP E t Applying 
a super-operator cannot increase the trace distance between two states: 

Fact 3.1. For a super- operator £ and density matrices p and a, \\£{p) — £(o")||tr < \\p — 0"||tr- 
Proof. Let 5 — p — a and let 6± = ± 6). Then S± >z 0, 6 = 5 + — 8- and \S\ = 5 + + 5_, implying 
\\€(p) ~ £(v)\\tr < || E fc ^+4lltr + II E k E k S-El\\ tr = Tr £ fc ^|5|4 = Tr = \\S || tr . □ 

An isometric super-operator not change the trace distance: ||£'AE r ''||tr = ||^4||tr for an isometry E. 

A measurement with finitely many outcomes can be defined as a super-operator £ in which 
the Kraus operators have the form E k = \k) <g> F k E £(H,CW ® ft'), for k E [d]. Then £(p) = 
® E kP E l is a block-diagonal matrix, known as a classical-quantum state or cq-state, in 
which the first register labels the classical measurement outcome fc, and the block F k pF^ is the 
resulting quantum state times its probability. 

The Holevo-Helstrom theorem [NCOO] states that for any states p and a, the maximum over 
all possible measurements £ of the total variation distance between the distributions of outcomes 
for £{p) and £(cr) is ^||p — <r||tr- This can be most compactly phrased as 

sup Tr(ILA) = |||>l||tr (3.1) 
o^n^i z 

for any Hermitian operator A with Tt A = 0. Since the trace distance between two states that are 
block-diagonal in the same basis is the sum of the trace distances between the corresponding blocks, 
one can also bound the expected trace distance between the resulting states F k pF^ k j Tr(F^F^p) and 
F k oFl/Tv{FlF k o): 



Lemma 3.2. Let p® = £ fc \k){k\ ® pf , for i = 1, 2. Let e = \\pW - p^\\ ti = J2 k \\pk } ~ P^IL 
Let be a random variable distributed according to Pt[K^ = k] = Tr p^ . Then the total 
variation distance between the distributions of and satisfies 



2 ^ 

k 



^{pr-pr)\<^ ■ (3-2) 
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Furthermore, letting p^ = p^/Trp£, if p^ ^ 0, and otherwise, the expected trace distance 
between and satisfies 

Proof. The bound on the total variation distance is a special case of the Holevo-Helstrom theorem, 

I tr * 



and follows directly from the inequality | Tr(p^ — p^)\ < Tr \p^ — p^ \ — — p^\ 



For the second part of the lemma, observe: 
Claim 3.3. For any c > and any two density matrices a and r, \\a — r||t r < 2||cr — cr||t r - 

Proof. By symmetry, we may assume without loss of generality that c E [0, 1]. Indeed, if c > 1, then 
\W - cr||tr = c||r - ~<j||tr > ||t - ^cr|| tr , and l/c e [0, 1]. 

For a Hermitian matrix M, let M± = \{\M\ ± M) y 0. Then 

||cr - cr||tr = Tr(cr - cr) + + Tr(a - cr)_ > Tr(a - cr) + > Tr(a - r)+ . 

Here the second inequality follows since by Schur's Theorem [Bha07] and as (1 — c)r h 0, Tr(a — 
ct) + — maxo^n^i Tr H(a — r+(l — c)r) > maxo^n^i Tr H(a — r) — Tr(a — r)+. Finally, Tr(cr — r) + — 
|||cr — r|| tr since Tr a = Tr r. □ 

Therefore, 

prilnW _n< 2 ) II 1 - VTr/) (1) ll/) (1) -/) (2) ll 
^LII^(i) ^(i)lltrJ _ Pfc lltr 

k 

(l)\\Jl) 1 (2)|, 



<2 E ^^ll^-^JpyP? 



Itr 



<2\\pM-p<»\\ tt . □ 
By a triangle inequality, a converse statement also holds: 

iip (1) - P (2) ik r < E MP - P f)\ + E^p^npf - pf 'ii* • ( 3 - 4 ) 

Thus for measurement super-operators £ and J 7 , £(p) is close to J 7 {a) in trace distance if and only 
if the distributions of measurement outcomes are close in total variation distance and the expected 
trace distance (under either measurement distribution) between the corresponding resulting states 
is small. In general, both of the latter conditions are required for the implication that £(p) ~ ^ r ( cr ) 5 
but we will argue later that in certain special cases, e.g., p — a — 1%/ dim?/, the maximally mixed 
state, and T a computational-basis measurement, it suffices that the expected trace distance between 
the resulting states be small. See Lemma 6.18. 

An essential proposition in our analyses of sequential CHSH games and state and process 
tomography is the so-called Gentle Measurement Lemma. It states that if a particular measurement 
outcome occurs with high probability on a given state p, then that measurement does not much 
disturb p: 

Lemma 3.4 (Gentle measurement [Win99, ON07]). Let p be a state, and II an operator with 
r< n r< 1. Then 

\\p - VUpVu\\tr < 2Vl-Tr(IIp) . (3.5) 
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A useful special case is when II can be written as tt ® 1 for a rank-one projection tt. Then the 
Gentle Measurement Lemma implies that p is close to a product state: 

Corollary 3.5. Let p be a state on Hi ® %2, and let tt be a pure state on %\. If for some 8 > 0, 
Tr(yrTr 2 p) >l-6, then 

\\p - tt ® Tri p|| tr < 2y/S + S . (3.6) 
Proof Substitute into Lemma 3.4 II = tt ® 1. Since TV (lip) = Tr(7rTr2 p) > 1 — 5, we obtain 

||p-7r®TVi((7r® l)p)|| tr < 2V5 . 
To finish, use ||TVi p - Tr x ((tt ® l)p) || tr = ||TVi((l - tt) ® l)p|| tr = Tr((l - tt) ® l)p < 5. □ 

This corollary can be generalized to say that if p is a multi-partite state whose partial traces are 
close to pure states ttj, then p must be close to the tensor product • ttj: 

Lemma 3.6. Let p E £(%i®- • "®H m ) be a quantum state. For j E [m], let pj = TV 1 m p E C{T~Lj) 

be its reduced density matrix on %j. Assume that for some 5 > and for each j E [m] there exists 
a pure state ttj E C(Hj) such that Ti^TTjPj) > 1 — S. Then 

\\p-7rx ® ••• ®vr m || tr < m(2VS + S) . (3.7) 

Proof. By Corollary 3.5, ||p — 7Tj ® Trj p|| tr < 2\/5 + 5 for all j. Putting these bounds together, 

||p - 7Tl ® • • • ® 7T m || tr < ^ ||tTi ® • ■ -7Tj_i ® (Tri...j_ip - 7Tj ® TVi...jp)|' 



Itr 

je[m] 

^ ||/>-^® Tr iHltr 

je[m] 
<m(2V8 + 8) . 

The second inequality holds because a partial trace cannot increase the trace distance. □ 

Note that the lemma would also hold, with the same basic proof, if one of the states ttj, say 7r m , 
were mixed and satisfied the assumption \\p m — 7r m ||t r < 2y/S + 6 instead of Tr(7r m p m ) > 1 — 5. 

Let us conclude this section with two more straightforward technical claims about the trace norm. 

Lemma 3.7. For a Hilbert space T-L and linear operators A and A in C(H), |Tr(^4A)| < ||^4|| || A|| tr . 

Proof. Let A = ^ • be the singular- value decomposition for A, for singular values Xj > 

and orthonormal sets {\j}} and {I/)}. Then, since || A|| tr = J2j ^ji 

\Tr(AA)\ = \Z^j(mj)\ < < \\A\W\Mtr • □ 

Claim 3.8. For any two unit vectors \a) and \b), 

min |||a) - e^|6)|| < \\\a)(a\ - \b)(b\\\ tr < 2\\\a) - \b)\\ . (3.8) 

0€[O,2tt) 

For arbitrary vectors \a) and\b) with \\\a) — \b)\\ < 5, \\\a)(a\ — |6)(6|||tr < ^/4|||a)|| 2 5 2 + 4|| fa) \\5 3 + S 4 . 

Proof. Calculate \\\a)(a\ - \b)(b\\\ tI = V(|||a)|| 2 + |||^)|| 2 ) 2 - 4|(4^p. For unit vectors, therefore, 
with 9 = arccos|(a|6)|, min^ || \a) - e^\b) \\ = y/2 - 2 cos 9 and \\\a)(a\ - \b)(b\\\ tr = 2sin<9. The 
assertions follow. □ 

Thus the trace distance between two pure states is closely related to their Euclidean vector 
distance up to a choice of phase. 
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Alice's strategy Bob's strategy 

a = a = 1 6 = b= 1 

|0)(0| i-> x = |+)(+| x = Gt|+)(+|G -> y = Gt|0)(0|G y = 

|1)(1| ^ x = 1 j-X-l x = 1 Gt|-)(-|G y = 1 Gt|l)(l|G y = 1 




Table 1: An optimal quantum strategy for the CHSH game. Alice and Bob each have one qubit of a 
shared EPR state -^(|00) + |11)). On each input a or 6, they make the two-outcome projective 

measurements listed above. Here, |±) = ^(|0) =L |1)) and G — exp(-i^Y). Thus Rq = Z, Rf = A, 

Rq = G^XG and i?f = G^ZG. The measurements are also illustrated on a cross-section through 
the xz-plane of the Bloch sphere. 



4 The CHSH game is rigid: A robust converse to Tsirelson's 
inequality 

In this section, we will study the CHSH game of Figure 2. We will argue that nearly optimal 
quantum strategies must, up to local changes of basis, be close to the ideal strategy that uses a 
shared EPR state, possibly in tensor product with an ancillary state. 

To avoid conflicting with the Pauli matrices X and Y , we will use lower-case letters a, 6, x, y for 
the random transcript in this section. Recall that Alice and Bob win the game if the exor of their 
responses equals the product of Eve's questions, x © y = ab. In computer science terminology, the 
devices Alice and Bob are referred to as "provers," and the experimentalist Eve is a "verifier." 

In a general quantum strategy, Alice and Bob have Hilbert spaces Ha and He, respectively, and a 
shared pure quantum state |^) E Ha®Hb®Hc- Here He is an inaccessible third Hilbert space used 
to purify the shared state. Alice and Bob determine their outputs by applying POVMs, depending 
on a and 6, respectively, to their portions of By possibly appending ancilla states, we may without 
loss of generality assume that they apply two-outcome projective measurements. (See also [CHTW04, 
Prop. 2].) For D e {A,B} and a,x E {0, 1}, let P D {a 1 x) be the projection applied by prover D 
for question a and answer x- Let R^ = P D {&, 0) — P D (a 1 1). Since P D (a 1 1) = — P D (a 1 0), 
R% is a reflection. Define the strategy's correlation value to be 

4(2Pr[a6 = a;© 1 /]-l) = ^|( £ (-l) ab R^ ® fl? ) ® l Hc • (4-1) 

a,6e{0,l} 

An example of a strategy that uses a shared EPR state \ip) = -^(|00) + |11>) is given in Table 1. 
This strategy satisfies that conditioned on any fixed values for a, b and x, the probability over y that 
the provers win is cos 2 |. Tsirelson's inequality [Tsi80] states that this strategy is optimal: for any 
quantum strategy, Pr[a6 = x © y] < cos 2 | = |(1 + « 85.4%. Therefore, the correlation value is 

at most 2y2. In contrast, for any classical strategy based on a shared random string instead of a 
shared quantum state, the maximum probability of winning is 3/4. 

Our CHSH rigidity lemma, a robust converse to Tsirelson's inequality, states that any strategy 
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that achieves correlation value at least 2\f2 — e must be 0(y/e) close to the ideal strategy of Table 1. 
In Appendix A, we prove a similar statement for an extended CHSH game in which the ideal 
strategy also includes measurements in the y direction of the Bloch sphere. 

Definition 4.1. For e > 0, a quantum strategy for the CHSH game is e-structured if the correlation 
value is at least 2y/2 — e. 

Lemma 4.2 (CHSH game rigidity). There exists a constant c > such that the following statements 
hold. Consider a quantum strategy for the CHSH game, specified by Hilbert spaces Ha, Hb and 
He, a state E Ha <8> Hb ® He, and reflections E C{Hd) for D E {A, B} and a E {0, 1}. 
Let e > and assume that the strategy is e-structured. 

Then there are extensions of the Hilbert spaces Ha,Hb, and extensions of the reflections R® by 
a direct sum with other reflections, so that the following properties hold: 

• There is an isomorphism between Alice's extended space and G 2 ®Ha, under which Rq = Z®1 
and \\(Rf - X <g> 1)^ <g> 1bc|^)|| < c^fe. 

• Bob's space is isomorphic to C 2 ® Hb, with Rq = Z <S> 1 and \\(Rf — X <S> 1)b\^)\\ < c^fe. 

• Finally, letting 

m = (i®{HG))±={m + \ii)) , (4.2) 

there exists a unit vector \ip x ) E Ha ® Hb ® He with - |^*) |^ x )|| < Cy/e. 

Furthermore, if Ha and Hb are finite-dimensional, then the isomorphisms into C 2 ®Ha and into 
C 2 ® Hb depend only on R^Rf and on R^Rf, respectively. 

Up to the constant factor, the 0(y/e) dependence of the error terms is tight. Indeed, if one 
starts with the ideal strategy of Table 1 and perturbs either the shared state or the measurements 
by 5, the correlation value will generically decrease by 0(5 2 ); first-order corrections must cancel. 

In our main applications of Lemma 4.2, the spaces Ha and Hb will be finite-dimensional. 
The final statement in the lemma is important because we would like the isomorphisms into 
C 2 ® Ha and C 2 ® Hb to be computable locally even without knowing the underlying state 
Indeed, after playing multiple CHSH games in sequence, neither prover knows |^). However, the 
dimension-truncation argument given below depends on 

For the proof of Lemma 4.2 we will use the following characterization of the eigen-decomposition of 
the product of reflections due to Jordan [ Jor75] . Its use is common in quantum computation, including 
in algorithms [Sze04, Reill, LMR+11], in amplification of QMA in complexity theory [MW05, 
NWZ09], and in the study of Bell inequalities in entanglement theory and device-independent 
QKD [Mas06, PAB+09, McK09]. 

Lemma 4.3 (Jordan's Lemma). Let II and A be projections acting on a finite- dimensional Hilbert 
space H. Then H can be decomposed into orthogonal one- and two-dimensional subspaces invariant 
under U and A. 

Before beginning the proof of Lemma 4.2, let us sketch the argument for the case that Ha — 
Hb — C 2 , He — C and e = 0. The rest of the proof essentially works by applying Jordan's 
Lemma to Rq and R^, and again to Rq and Rf , to locate Alice and Bob's qubits for the game 
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and therefore reduce to this two-dimensional case. However, achieving the optimal 0(y/e) error 
dependence requires more work. 

If the reflections act on C 2 and are not equal to ±7, then we can choose a basis such that 
Bg = Z,R*= (-s20 jm2^) and r b = (cob 2*; for certain angles ^ G [0, §]. Letting 

M = + i?f ) <g> I - -^J <g> and Mi = - 7 - -^J <g> i?f , the correlation value 

satisfies 

2V2-e<(^|( ^ (-ir fe ^®i?f)|^ = 2^-^|(M 2 + M 1 2 )|^) . 

a,6G{0,l} 

For e = 0, this means that must lie in the intersection of the kernels of Mq and M\. The four 
eigenvalues of Mq are ±cos# ± For the kernel to be nonempty, it must be that 9 = |. A 
symmetrical argument implies that 0' = |. For small e > 0, |^) must lie close to small-eigenvalue 
subspaces of both Mq and Mi, implying that and 6' are close to j. Thus the measurement 
operators are rigidly determined. 

For 9 = 6' = f , the kernel of y/2((HG) ® 7)M ((G t i7) ®J) = Z®J-J®Z is spanned by the 
vectors |00) and |11). The kernel of V2({HG) ® 7)Mi((G t i7) ®J) = X®J-J®X is spanned by 
the vectors |+) ® |+) = ±(|00) + |01) + |10) + |11)) and |-> ® |-) = ±(|00) - |01) - |10) + |11}). 
For the 1 01) and 1 10) terms to cancel out, a linear combination of these vectors must have equal 
coefficients. The intersection between the two kernels is therefore spanned by 1 00) + |11). Thus the 
state is rigidly determined. 

The above argument, together with Jordan's Lemma, conveys much of the intuition for the 
CHSH rigidity lemma. However, we have not explained the derivation of the operators Mq and Mi, 
chosen to satisfy Ea,6e{o,i}( _1 ) a6i? a ® i?f = 2y/2I ® I - V2(M$ + M x 2 ). In general, for a game 
in which Eve draws her questions from the distribution p(a, b) and accepts if x © y = V(a, 6), let 
6 = J2 a bP( a ' ^)( — l)^ a '^|a)(6| and @ = (@t o)' u * ^ e ^ e °P^ ma l success probability. By the 
Tsirelson semi-definite program [CSUU08], the optimal bias is 2a; * — 1 = \ maxr>o,roi=/(©, T) = 
| min A=Aoi> ^Tr A. T is the Gram matrix of the vectors Ra\^) and R^\ip). Letting A* achieve 
the second optimum, we have |(6, T) = (2cj* - 1) - ±(A* - 9, T). For the CHSH game, A* = ^=1, 
and the matrices Mq, Mi correspond to eigenvectors of A* — O. 

Proof of Lemma J±.2. We begin the proof by truncating the Hilbert spaces T~La and %b to finite 
dimensions, in order to apply Jordan's Lemma. Jordan's Lemma is false for infinite-dimensional 
Hilbert spaces. 

Claim 4.4. For any S > 0, there are finite- dimensional subspaces Ha Q Ha, Q T~Lb such that: 

• For D E {A, B}, Hp is closed under Rq . 

• For D E {A, B} 7 there exists a reflection Rf E C(H D ) with \\(R% - i?f ) ® 1|^)|| < 6 and 
under which Tip is closed. 

• Letting be projected to %a ®T~Lb ®T~tc and renormalized, — |^)|| < 5. 

• The joint strategy specified by Alice's reflections Rq, Rf, Bob's reflections Rq , Rf , and the 
joint state has correlation value at least 2y/2 — e — 5. 
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Proof. First truncate the spaces Ha and Hb to finite dimensional spaces Ha and % b that are closed 
under Rf and Rf , respectively, and such that |^) is almost entirely supported on T-La ®tis ® He- 
For D E {A, £>}, let be the closure of tin under Rq . Let Rf be i?^ on tin extended by the 
identity on tip. In this way, Hd is closed under both Rq and .Rf. □ 

Using the assumption e > 0, apply Claim 4.4 with 5 = e. By Jordan's Lemma, Ha can be 
decomposed into the direct product of a set of one- and two-dimensional subspaces invariant under 
both Rq and Rf. For notational convenience, add dimensions and extend the reflections if necessary, 
so each subspace is two dimensional and includes both +l-eigenvalue and — 1-eigenvalue eigenvectors 
for both reflections. Index these subspaces by i. Similarly decompose tis according to Rq and Rf , 
indexing the invariant two-dimensional subspaces by i' . 

Let 0i G [0, |] be the angle between the +1 eigenvectors of Rq and Rf on the ith subspace, and 
let Ci = cos2#i and Si = sin 29 i. Define the angles 9^ similarly, and let CV = cos 26^/, SV = sin 29^. 
Choose orthonormal basis vectors |0) = (J), |1) = (?) for each subspace, so 

R o\ti A =X)l i X i l® Z 

i 

Since each 7^ cHd is closed under i?^, we can choose a basis for Hp C^d so that Hd — ti,D®C 2 
and Rq — 1® Z everywhere, by if necessary extending the Hilbert space Hd- This gives two of the 
claims of Lemma 4.2. 

With this decomposition, and letting {\c)} be an orthonormal basis for He, the shared state |^) 
can be written 

\^)abc = \ c ^c ® Ma ® N% ® 

c,i,i ; 

|^cm')aB = ^2 a cii'bb'\b) A ® |6')s • 
6,6'e{0,l} 

Let |^/) = |^ C u')/|||?/w)||. 

For j G {0, 1}, let = + (-1)^) ® l sc " ® Uc- Then 

2^2 - 2e < (^| (i# ®R(? + R$®Rf + Rf®R^ -Rf® Rf) |^) 

= 2V2-V2(M 2 + M 1 2 ) | ^ ) . (4 ' 3) 

In particular, letting f3 cii t = (M 2 + M l)\n>)®$ cii ,)> 

< (M 2 + M 2 )^ = ]T |fe)|| 2 /W < V2e . (4.4) 

Proposition 4.5. For am/ c, sin 26^ > 1 — 0(/3 c ^/) ; sin 20^ > 1 — 0((3 c a>) and for some 
phase 4> cii t, 

|||^)-e^|^*)|| 2 <0(/3 c ^) . (4.5) 



i 
i' 
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Proof. To simplify notation, we will suppress the c, i, i' dependence, and restrict the operators Mj 
to the invariant subspace. Then /3 = /3 cii > = ||M |^)|| 2 + ||Mi|^)|| 2 . Assume that (3 < 2 ■ 10" 6 ; 
by fixing the hidden constants in our desired inequalities to be sufficiently large, the claims are 
trivial for larger f3. 

Expanding |i/>) as \tp) = aoo|00) + aoi|01) + aio|10) + an|ll), and letting C = C{, S = Si, 
2M |</>) = aoo(l - \/2)|00) + a i(l + V^)|01) - «io(l + v / 2)|10) - a n (l - y/2)\ll) 



+ «oo 



( c\o) 
\+s\i) 



|0) + a i 



C|0> 
+S|1> 



-%)|0>+an 



5|0) 
-C|l) 



|f) + "10 

= |00) [aoo(l + C - V2) + a 10 S] + |0f) [a i(l + C + v^) + «nS] 
+ 1 10) [a 00 S - ai (l + C + v^)] + |11) [a iS - au(l + C - v 7 ^)] . 

For 6,6' G {0, 1}, let 5 W = 2(bb'\M \4>). Then |<W| 2 = 4||M |^)|| 2 < 4/3. We find 



|1) 



01 



1 + C + V2 



aio 



aooS" - (5 



10 



1 + C + V2 



implying 



aoo 



(1 + C - V2) + 



S 2 



<$oo + 



5(5 



10 



1 + C + V2 

The inequality uses |C|, \S\ < 1 and a Cauchy-Schwarz inequality. 
Claim 4.6. Either \a 00 \ > 1/2 or |an| > 1/2. 

Proof. Assume |a o| < 1/2- By Eq. (4.6) and since j3 < 1/100, 



l + C + ^/2 



<3y^ 



(4.6) 



(4.7) 



I I . |«00| + |^lo| . 2 

|«io| < ^ < 



5 + 2^ 1 

< — 

V2 2 



Symmetry under switching Alice and Bob implies |aoi| < \- Since J2 bb / |ow| 2 = 1 5 |c^n| > 1/2. □ 
Thus from Eq. (4.7) we determine 

s 2 



1 + C-V2 + 



1 + C + V2 



< 



6v^ • 



Multiplying both s ides by 1 + C + V2<2 + V2 gives |(1 + C) 2 - 2 + 5 2 | = 2\C\ < 21y/]3. As 
P < 2 ■ 10" 6 , S = Vl - C 2 > 1 - 61/3. By symmetry, sin 2Q V > 1 - 61/3, too. 
Now let us read off bounds for the coefficients a^b' from Eq. (4.6). First, 



«io - 



«oo 



a 00 S - 8 



10 



«oo 



1 + \[2 1 + C + V2 1 + V2 



< I «oo I 



1 + C + V2 1 + V2 



+ < 4 8v^ • 



By symmetry, |aoi — < 48-v 7 ^- By the same steps, |aio + J^/jl — 48y / /3- Hence, 

|an + a o| < Ian + (1 + V2)a w \ + |a 00 - (1 + V2)a w \ < 2(1 + ^2)48^ < 232 
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Putting these coefficient bounds together, we have 

|2 



1 



iw>r 



i^i 2 ~ i^ooi 2 ( 2 + 



< 1^11 1 



1^00 + 



«01 



(1 + v^) 2 



|«00 1 



(1 + V^) 2 



+ 



K*io 



|«00 | 



(1 + V^) 2 



< 2 • 232 + 2 • 48^/3 + 2 • 48^//? = 656^7/3 



where we have used \x 2 — y 2 \ — \x — y\ • \x + y\. In particular, it follows that if we let 
the argument of «oo, so that e _ ^«oo = |^oo| 5 

|aoo - e «><00|V> )| < < 429 V/? , 



7/ be 



and 



|||^)-e < V>ll 2 = El a »'- e ^ 66 'l^)l 2 

< (^429 2 + 2(^48 + ^^=) 2 + (232 + 429) 2 )/3 < 10 6 /3 
We now collect together our calculations to prove Lemma 4.2. Let 

\^) = Y J ^'\\\^)\\\^)cAB , 



□ 



a unit vector. We have, by Proposition 4.5 and Eq. (4.4), 

x \ 1 1 2 ^ T 1 1 1 ' * 1A ..,\w , \ 1 1 i / * \ 1 1 2 



IV*>®hHll 2 = £llhfe 



1^)|| =ElH^}ll 2 -o(/3 cii o = o( e ) 



This establishes the last claim in Lemma 4.2. It remains to argue that \{R^-X ®\) A \i>)\ and 
(Rf — X ® 1)^1^)11 are each of order y/e. From Claim 4.4 and a triangle inequality, we bound 
(Rf-X®l) A \t{;)\\ < 2S + 2\\\^) - |^*)|^ x )|| + \\(Rt-X® 1) A |^*)|^ X )||. To bound the last 



term, recall that on each subspace z, Rf acts as 



Si —Ci 



, and so 



(Rf-X®l) A \i,>W 



E 



C,l,l' 



Ci Si \ _ 

Si Ci 



C,l,l' 



which is again of order e by Proposition 4.5 and Eq. (4.4). A symmetrical argument bounds 
\\(R?-X®1) B W)\\. ' ' □ 

For later convenience in Section 5, let us state several simple technical corollaries of Lemma 4.2. 

Corollary 4.7. There exists a constant c > such that under the conditions of Lemma J±.2, it 
further holds that for e < c, each of the sixteen possible outcomes of the game, (a, x, 6, y) E {0, 1} 4 ; 
occurs with probability at least 1/60. 
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Proof. In an ideal CHSH game the probability of an outcome (a, x, 6, y) is ^(1 + ^) if ab = x © y 
and is ^(1 — 4^) > ^ otherwise. As e tends to 0, Lemma 4.2 implies that the probabilities of the 
different outcomes converge to these values, so for sufficiently small e all probabilities will be at 
least 1/60. □ 

Corollary 4.8. Under the conditions of Lemma 4-2, it further holds that for (D, D f ) E {(A, £>), (£>, A)} 
and a E {0, 1}, 

|| [R° ® - ^((Z + (-1) Q X) ® 1) D , ® 1 DC ] |</>) || = O(v^) - (4.8) 

Proof. This corollary says that Bob's measurements can be pulled over to Alice's side, or Alice's 
measurements pulled over to Bob's side. For an ideal CHSH game, this fact is a consequence of the 
identity ( a c b d ) ® J(|00) + |11)) = 7® U S)(l 00 ) + I 11 ))- Tne claimed bounds come from combining 
this with triangle inequalities from Lemma 4.2. For example, for a = 1, letting R— -^(Z — X), 

H - 1) D 'M|| < ||(i?f - ^ ® 1)d|^)|| + ||[(X ® 1) D - (i?® lM(l^) - hW»|| 

+ ||[(X®1) D -( J R®1)^]|^)|V X )|| • 

The first two terms on the right are each of order ^/e, and the third term is zero. □ 

Corollary 4.8 in turn implies that the expectation value of an observable localized to %a 
cannot change much, on average, over an e-structured CHSH game, since Alice's measurement 
can be pulled over to Bob's side. Recall that P D (a,x) — \iX + ( — l) x ^a)- Let |0(a,x,6, y)) — 
P A (a,x)®P B (b,y)\^) and \i/>(a, x, 6, y)) = \<t>(a,x,b,y))/\\\<f>(a,x,b,'< 



Corollary 4.9. Under the conditions of Lemma J.. 2, let \(f>) — \ J2 a x b ye{o 1} \ ( P( a ^ x -> ^ V)) ® 
| a, x, 6, y). Then for any operator M supported on Ha, 

|Tr(M® 1|^|) -Tr(M® 1|0)(0|)| = 0(y/e)\\M\\ . (4.9) 

Proof. By Corollary 4.8, there exist reflections R a supported on namely Ro = + and 

Ri = ±{-X+Z)®l, such that \\P A (a,xM - ±(1 + (-1)^)^)11 = \\\{{R*)a ~ {Ra) B )W)\\ = 
O(v^). Let \<f>'(a, x, b, y)) = P B (b, y)\{l+{-iyR a ) B \^) and \</J) = ±J2 axby \<f>\a, x, b, y)) \a, x, b, y). 
Then \\\4>(a,x,b,y)) ~ \<f/{a,x,b,y))\\ = 0(y/e) and so |||0) - |<//)|| = 6(je). Now Tr M\^\ = 
Ti: M\(j)')((j)'\, since M is supported on %a and the projections P B {b,y) and |(1 + (— l) x R a ) are 
supported ohI-Lb- Therefore, by a triangle inequality, 

|TrM^}(V|-TrM|0)(0|| < |TVM(|^| - l<Wl)l < 2||M|||||$ - \<j>')\\ = 0(Ve)\\M\\ . □ 

Similarly, in any structured CHSH game, the states resulting from different game outcomes are 
approximately related by single-qubit unitaries: 

Corollary 4.10. For a, a 7 , A E {0, 1} ; there exist single-qubit unitaries J7(a, a',A) such that 
for sufficiently small e > and any e-structured CHSH game where Alice plays using the ideal 
measurements from Table 1 on her first qubit, it holds that for all a, x, a', x', 6, y E {0, 1} ; 

\i/>(a,x,b,y)) - {U{a,a',x®x')®l) A \^{a!,x',b,y)) = 0(y/e) . (4.10) 
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Proof. Consider an ideal CHSH game, with e = 0. Then the unitaries U(a, a', x © x') can be read 
off Table 1. For example, if a = a', the Pauli X operator switches the two outcomes of a Pauli Z 
measurement and vice versa. Thus U(a, a, 0) = 1, £7(0, 0, 1) = X and £7(1, 1, 1) = Z. The specific 
forms of the unitaries are not important. 

Now for an e-structured CHSH game with e smaller than a certain positive constant, both 
denominators in Eq. (4.10) are nonzero, so the left-hand side is at least well-defined. The claimed 
bound follows by applying the CHSH rigidity lemma to relate to |^*) ® \^ r ) for |i/>*) an EPR 
state and some |?//), and several triangle inequalities. □ 

Finally, the effect of the game can be duplicated by having only Alice make her measurements 
and then applying a unitary correction to Bob's qubit: 

Corollary 4.11. For a, 6, A G {0, 1}, there exist single-qubit unitaries V(a, b, A) such that for suffi- 
ciently small e > and any e-structured CHSH game where Bob plays using the ideal measurements 
from Table 1 on his first qubit, it holds that for all a, x, a', x', 6, y E {0, 1} ; 

P A (a r)Wb) 

|^(a, x, 6, y)) - (V(a, 6, x y) 1) B q ' ^jg „ = 0(y/e) . (4.11) 



Proof. In an ideal CHSH game, there certainly exist unitaries V(a, b,x © y) relating, up to normal- 
ization, P A (a,x) ® P B (b,y)\i(j) to P A (a,x)|^), since Alice's measurement collapses the shared EPR 
state leaving Bob's qubit in a tensor-product state. The argument for an e-structured CHSH game 
is now the same as in the proof of Corollary 4.10. □ 



5 Sequential structured CHSH games have a tensor-product 
structure 

In this section, we will argue that if two provers play n sequential CHSH games in such a way that 
for every j, game j is e-structured most of the time, then the provers must share a state close to n 
EPR states and most of the time their strategy for game j must be nearly equivalent to the ideal 
CHSH game strategy acting on the jth EPR state. 

The proof uses Lemma 4.2 repeatedly to simplify the provers' strategies and extract EPR states. 
It is not enough to correct the games one at a time, in sequence. Although the first game is 
e-structured, and therefore 0(v^)-close to the ideal strategy on an EPR state, correcting this first 
game will introduce an 0(y/e) error into all subsequent games. This leaves the second game only 
0(v^)-structured, so correcting it introduces an 0(e 1 ^) error into subsequent games. Thus with 
this naive argument, the error snowballs, both from the e — > y/e dependence of Lemma 4.2 and 
from the exponentially accumulating renormalization factors. Other natural arguments face similar 
problems. To obtain only a polynomial blowup in the error parameter e, the argument is surprisingly 
involved, following the proof sketch in Section 2.2. 



5.1 Notation 

To make our claims precise, we begin with some notation for CHSH games played in sequence, one 
following the next, with no communication between games. 
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Definition 5.1 (Notation for sequentially repeated CHSH games). A strategy S for two provers, 
Alice and Bob, to play n sequential CHSH games consists of the provers 7 Hilbert spaces, their initial 
state and the reflections they use to play each game. Fix the following notation: 

Transcripts: Denote questions asked to Alice by ai, . . . , a n , questions asked to Bob by &i, . . . , b n , and 
possible answers by x\, . . . , x n and j/i, . . . , y n , respectively. Write = (ai, . . . , a^, xi, . . . , Xj), 
h? = (61, . . . , bj, yi, . . . , yj) and hj = (h^, h?), a full transcript for games 1 through j . 
Similarly write hj^ and h® k for the full or partial transcripts for games j through k, inclusive. 

Hilbert spaces: Let %a and %b be the two provers' Hilbert spaces, and %c any external space. 

Reflection and projection operators: In game j, for questions aj and bj, let Ra^hf-i) and 
Rh.(hf-i) be the reflections specifying Alice and Bob's respective strategies? Let P^{h^) — 
+ (/*/_!)) andP?{hf) = \{l + {-l)VjB$ j {hf_ 1 )). For D e {A, B} andj<k, 

let P° k (h°) = P k D (h°) ■ ■ ■ Pj> +1 (h? +1 )lf(hf). Let P f(h k ) = P£ k (h£) ® P* k (h B k ). 

A\h A B\h B 

Super-operators: For j < k and partial transcript hj, define super- operators £ k 1 j and £ k 1 j by 



^(|^ + i, fc _iX^ + i,fc-il ®p) = \ E ® P£(h£) P p k A (h£) 



2 

£^ h h\hf +l , k - l )(hf +l , k . l \® P ) = \ £ \hf +l , k )(hf +hk \ ® If {hf) P I?{ht 

bk,Vk 



(5.1) 



These super- operators capture the effects of Alice and Bob playing game k, where games j + 1 
to k — 1 of the transcript are stored in a separate register. For £ > k and D E {A, B}, let 

p D\hf _ p D\hf p D\hf p D\hf j p AB\h 3 _ p A\hf ~B\hf 

States: Let \^) E %a ® T~Lb ® %c be the provers 7 initial shared state, and let \ip(hj-i)) be the shared 
state at beginning of game j conditioned on the transcript hj-\; it is given by 

p if i(Vi)l^) 

WW) - ^t^JL ■ (M) 



We adopt the convention that if the numerator above is ; then \ip(hj-i)) = 0. For notational 
brevity, we will commonly suppress the dependence on the transcript and write simply ifjj. 

Let Pl = \^\, Pj = £ff_M) = ikr E hj , ® ^i(^-i)Pi^-i(^-i) t , ™d 

p(h j - 1 ) = W(h j - 1 )Mhj-i)\- 

Random variables: We use Aj, Bj, Xj,Yj to denote the random variables for the questions and 
answers in game j, and Hj for the transcript up through game j. Aj and Bj are dis- 
tributed independently and uniformly at random. Conditioned on the transcript hj-i for 
the first j — 1 games and the questions aj and bj, Xj and Yj are distributed according to 
Pr[Xj = Xj ,Yi = yjlHj-! = h^Aj = a^Bj = bj] = \\Pf(hf) ® Pf (hf )|</>(^-i)> || 2 . Then 
Pj = Efc, x Pr[flj-i = hj-!] IV1XV1 1 ® \Hhj-i))(Hhj-i)\. 



3 Although the provers' reflections for game j may, without loss of generality, be taken to be independent of previous 
measurement outcomes, allowing such dependence will be convenient for specifying alternative strategies. 
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Other strategies: When considering multiple strategies, say S and 5, we will decorate the above 
notation to indicate the corresponding strategy. For example, \ijj(hj-i)) denotes the shared 
state at the beginning of game j conditioned on the transcript hj-\, with play according to S. 

Recall from Definition 4.1 that an e-structured CHSH game is one with a correlation value at 
least 2y2 — e. In our theorem, we will assume that most games the provers play are e-structured, in 
the following sense: 

Definition 5.2 (Structured strategy). A strategy S for n sequential CHSH games is (5, e)-structured 
if for every j, Pv[game (j, Hj-i) is e-structured] >1 — S. S is e-structured if it is (e, e) -structured. 

Our goal is to show that the provers play close to an ideal strategy, defined as in Table 1 by: 

Definition 5.3 (Notation for an ideal CHSH game). Let |^*) = ^(|00) + |11)) E C 2 ® C 2 . For 
x E {0,1}, let \(0,x) A ) = \x) and \(l,x) A ) = ^(|0> + For b E {0,1}, let \(b,0) B ) = 

cosf |0) + (-l) 6 sin||l) and |(6,l)s) = sin f |0) - (-l) 6 cos f |1). For D E {A, B} and a E {0,1}, 
let R° = \(a, 0)D)((a, 0) D | - |(a, 1)d)((«, 1) d |. 

Let A,B,X,Y be random variables distributed according to the outcomes of the ideal CHSH 
game, Pr[(i, 5, X, f) = (a,b,x,y)] = \\\ \{1 + (-1) X R^) ® \{1 + (-l) y i?f )|^*) || 2 , which equals 
\ cos 2 I if ab = x ®y and \ sin 2 | otherwise. 

Definition 5.4 (Ideal strategy). A strategy S for n sequential CHSH games is an ideal strategy 
if there exist isometries X A : U A ^ (C 2 )® n ® U' A and X B : U B ^ (C 2 )® n ® H' B and a state 
\^) E T~L' A T-L' B %c such that for every j and hj-\, 

X A ®X B W) = \rf n ® W) Raihf^) = T D \R»)fL D , (5.3) 

where (R^)j denotes the ideal operator from Definition 5.3 acting on the jth qubit. 

We will want to compare strategies in order to argue that the provers' actual strategy is "nearby" 
a better-behaved strategy. For this purpose, we introduce the following notion of strategy simulation: 

Definition 5.5 (Strategy simulation). Let S and S be two strategies for playing n sequential CHSH 
games. For e > 0, we say that strategy S e-simulates strategy S if they both use the same Hilbert 
spaces and for all j, 

max \\£°( P1 ) - 5g-(pi)||tr < e . (5.4) 

De{A,B} :J ,J 

Say that S weakly e-simulates S if only the weaker inequality \\£^f(pi) — £^(pi)||t r < 2e holds. 

It is also convenient to allow a basis change by local unitaries or local isometries: 

Definition 5.6. A strategy <S is an isometric extension ofS if there exist isometries X D : T~L B c_ ^ Hd, 
for D E {A,B}, such that \$) = X A ® X b \^j) and X D R^(hf_ 1 ) = R^hf^X always. (Thus 
X D £f = £fX D and X A ® ?d B \^(h j - 1 )) = ^{hj^)).) 
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5.2 Main rigidity theorem and proof outline 

Our main theorem states that a structured strategy can be closely simulated by an ideal strategy: 

Theorem 5.7 (Main rigidity theorem for sequential CHSH games). There exists a constant such 
that for any e-structured strategy S for n sequential CHSH games, letting £ = K^n^e 1 /* 1 * , there 
exists an ideal strategy S that (^-simulates an isometric extension of S. 

The proof of Theorem 5.7 is sufficiently involved that an outline should be useful. See Figure 4. 
The first step of the proof is to replace the structured strategy S with one in which the provers play 
every game using the ideal CHSH game operators on some qubit, up to a local change in basis. 

Definition 5.8 (Single-qubit ideal strategy). A strategy S is a single-qubit ideal strategy if there 
exist unitaries U^ih®^) : T~Ld — ^ C 2 ® T~L f D such that always 

That is, each proverbs reflections for game (j, h^_^) are equivalent up to local unitaries to the ideal 
CHSH game reflections of Definition 5.3, but the qubits used need not be in tensor product. 

Theorem 5.9. There exists a constant n such that if S is an e-structured strategy for n sequential 
CHSH games, then there is a single-qubit ideal strategy S that nn^e 1 ^ -simulates an isometric 
extension of S. 

Next, we find a nearby strategy in which the qubits for successive games are in tensor product. 

Definition 5.10 (Multi-qubit ideal strategy). A strategy S is a multi-qubit ideal strategy if 

there is a unitary isomorphism y D : T~Ld —> (C 2 )® n ® T~L' D under which for unitaries M^{h^_^) E 
£(( C 2)®(n-j+i) n ^ such that 

(5.6) 

That is, S is a single-qubit ideal strategy in which the qubits used in each game must lie in tensor 
product with the qubits from previous games. 

Theorem 5.11. There exists a constant k such that if S is an e-structured single-qubit ideal strategy 
for n sequential CHSH games, then there is a multi-qubit ideal strategy S that nn^e 1 ^ -simulates an 
isometric extension of S. 

The last major step in the proof of Theorem 5.7 is to argue that the qubit locations cannot 
depend significantly on the local transcripts, and therefore simulate a multi-qubit ideal strategy 
with an ideal strategy. 

Theorem 5.12. There exists a constant n such that if S is a (5 \e)- structured multi-qubit ideal 
strategy for n sequential CHSH games, then there exists a transcript h n such that S is Kn K (8 + e) 1 ^- 
simulated by the ideal strategy <S that uses the qubits defined by h n in S. That is, using the notation 
of Definitions 5.4 and 5.10, S is defined by 

1 D = (V)®(«-D ® M°(h°_i)) ■ ■ ■ M?y D . (5.7) 
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The proofs of Theorems 5.9, 5.11 and 5.12 are given, respectively, in Sections 5.4, 5.5 and 5.6 
below. To chain these theorems together, we will use: 

Lemma 5.13. Let S be a (5, e)-structured strategy for n sequential CHSH games. If S is a strategy 
that weakly rj-simulates S, then S is (5 + 2y/rj, e + W^/rj) -structured. 

Proof. By definition of weak ^-simulation and Lemma 3.2, dxv (Hj-i, Hj-i) < \\pj — Pj\\t r /2 < r\ 
for all j. In particular, therefore Pr[game (j, Hj-i) is e-structured in S] > 1 — S — 77. 

For random variables (A, B) and (A', B') in the same space, J2 a P r [^ = a]dTv(B\A = a, B'\A' — 
a) < 2drv ((A B), (A', £>')). Applying this and a Markov inequality to (Hj-\,Hj) and (Hj-i,Hj), 
we get that with at most a y/fj probability over Hj-i can the total variation distance between the 
outcomes of playing strategy S and of playing strategy S in game (j, Hj-i) be greater than 2y/rj. 
By Definition 4.1 for structure and a union bound, therefore Pr[game (j,Hj-i) is e-structured in S 
and (e + 16y / r/)-structured in S] > 1 — 5 — 77 — y/rj. □ 

Theorem 5.7 therefore follows from Theorems 5.9, 5.11 and 5.12. 

We begin the proofs of the latter theorems by reducing to the case where the Hilbert spaces Ha 
and Hb are finite dimensional. This is necessary to ensure that the strategies given by the CHSH 
rigidity lemma applied to games 2 through n depend only on the local transcript hP and not on 
the full transcript h. Although the CHSH rigidity lemma itself holds even for infinite-dimensional 
Hilbert spaces, the dimension-truncation argument it uses depends on the underlying state and 
therefore potentially on the full transcript. 

Lemma 5.14. Assuming that Theorem 5.7, 5.9, 5.11 and 5.12 hold whenever the provers' Hilbert 
spaces Ha and Hb are finite dimensional, the theorems also hold in general. 

Proof. We claim that for any strategy S on possibly infinite-dimensional Hilbert spaces Ha and Hb-, 
and for any parameter 5 > 0, there exists a strategy S that 5-simulates <S, such that there exist 
finite-dimensional subspaces H! A C Ha and H! B C Hb that are closed under all of the operators 
Rj^ a and Rj^ and such that is entirely supported on H! A ® H' B ® He- 

Provided this claim holds, Theorem 5.7 can be applied to S restricted to H! A and H' B , yielding 
an ideal strategy S that e-simulates an isometric extension of S. Theorem 5.7 follows by extending 
the isometries to all of Ha and Hb- The other theorems follow similarly. 

To establish the claim, assume that in fact one or both of Ha and Hb are infinite dimensional. 
Let H^ A C Ha and H^ B C Hb be finite-dimensional subspaces such that p^\ the renormalized 
projection of I^X^I to H^ A H B ® Hc-> is 5-close to |^)(^|. Then Alice and Bob's actual strategy 
is 5-simulated by the same set of measurements applied to p^ E C(Ha ®Hb ® He)- 

The proof is not yet complete, since H^ A and H^ B will generally not be closed under the provers' 
operators R^ a and R'- h . We fix this one operator at a time. Order Alice's reflection operators as 
Si, S2, . . . , S m , such that reflections for earlier games come before reflections for later games. For k 
from 1 to m, let H^ A be the closure of H A ^ under Sk and extend each Sj for j < k by the identity 
on (H A 1 ^)~ L . By this construction, for any vector \v) E H^ A and any ai, . . . , a m E {0, 1}, the state 
... S^Sl 1 \v) lies in H { A \ Therefore there is no loss in truncating Ha to H^ A \ Finally apply 
the analogous procedure for Bob to obtain space H^ that is finite dimensional and closed under 
each of Bob's operators. □ 

Henceforth we will always assume that Ha and Hb are finite dimensional. 
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5.3 How to play for Bob without measuring % B 



Before continuing the proof of Theorem 5.7, it will be useful to argue that a structured strategy 
can be closely simulated by alternative protocols in which only one of the two provers makes 
measurements. 

Since for any matrix M E £(C 2 ), (M ® 1)(|00) + |11)) = (1 <g> M T )(|00) + |11)), operations on 
one half of an EPR state can equivalently be performed on the other half. This allows us to show 
that a structured protocol for playing sequential CHSH games can be simulated by either of two 
hypothetical protocols in which Alice receives Bob's questions and answers for him. Studying these 
simulations has a key conceptual advantage over studying the actual protocol: if when given bj 
only, Alice can play for Bob in game j, then Bob's strategy for game j intuitively cannot depend 
on the outcomes h^_ x of the prior games. There are also technical advantages. For example, one 
of our main concerns is that the qubits Bob uses in two successive CHSH games might overlap. 
However, if we switch Bob's measurements for the second game over to Alice's side, then, since T~La 
is in tensor product with Us, they necessarily act on qubits in tensor product with Bob's qubits for 
the first game. 

5.3.1 First hypothetical protocol: Alice guesses Bob's measurement outcomes 

In the first hypothetical protocol, Alice plays her games as usual, but also receives Bob's questions bj. 
Alice guesses Bob's answers and gives them to Bob, who merely applies certain unitary corrections. 
We will argue that this protocol generates states nearly indistinguishable from the results of a 
structured strategy for n sequential CHSH games. 

This alternative protocol is only hypothetical, since it requires information and communication 
not allowed in sequential CHSH games. However, it is technically simpler to analyze since only one 
of the two provers makes any measurements. 

Before defining the alternative protocol, it will be useful to define the qubit used in game (j, h?_^) 
for each prover D: 

Definition 5.15 (Game qubits). Let S be a strategy for n sequential CHSH games. For D E {A, B} 
and for each partial transcript h®_ l9 let (3 index a complete, irreducible set of orthogonal one- 
or two-dimensional subspaces of T~Ld that are invariant under R^h^^) for a E {0,1}. Let 
U ?( h ?-i"> : Ud ^ C<2 ®7-L' D be an isometry such that U 3 D (hf_ 1 ) t (l ® \f3)(fi\)Uf {hf^) is a projection 
onto subspace (3, chosen so that for dihedral angles 0p{h^_^) E [0, 7r/2] ; 

Jtf = Uf{hf_ x ?{Bg ® l)UP{hf_ x ) 

RtihU) = uf( h ^(j:{ZlZ -tfi) ® iwiK(^-i) , 

p (5.8) 

We refer to the first register in the codomain of 'U^ \h®_ 1 ) as the u qubit used in game (j, h^^)." 

Such isometries exist, provided Ha and T~Lb are finite dimensional, by Jordan's Lemma 
(Lemma 4.3) but they are generally not unique. Eq. (5.8) simply specifies a convenient basis 
for the two-dimensional subspace Range(l ® \/3)(/3\). However, up to this freedom in choosing the 
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subspaces, and up to the choice of basis within each subspace, the isometries U^{h^_^) and U^{h^_^) 
are the same isometries as promised by the CHSH rigidity lemma, Lemma 4.2, for game (j, hj-i). 

The maps U^{h^_^) are generally isometries and not unitaries because there may be some 
one-dimensional invariant subspaces (3 and it is notationally inconvenient to have a separate term 
for this case in Eq. (5.8). It is not difficult to argue, though: 

Proposition 5.16. Provided Ha andl-Ls are finite dimensional, there exists an isometric extension 
of the provers' strategy S into finite- dimensional spaces such that the operators ?7^ ) (/i^_ 1 ) are all 
simultaneously unitary. 



Proof. Choose an arbitrary order for all the partial transcripts hj_ 1 , j E [n]. One transcript at a 
time, add dimensions to T~Ld so that U^{h^_^) is unitary. The concern is that this could break 
previously considered operators. After the first extension dim(7^ j c>) is even, however, so there 
are always an even number of one-dimensional invariant subspaces /?, so always an even number of 
dimensions are added to Hd- These dimensions can be paired up arbitrarily in the previous 
operators, so that they still each unitarily expose a qubit. □ 

If S is a single-qubit ideal strategy, then the U^{h^_^) satisfy Eq. (5.5) in Definition 5.8, and in 
this case the prover's reflections for game (j, are only supported on that one qubit. In general, 

though, the angles Op will depend on /3 and there does not exist a basis change under which the 
prover's reflections for a game are supported on just one qubit. 

Now we are ready to define the super-operators for the alternative protocol mentioned above. 



by 



Definition 5.17. Let S be a strategy such that the operators U^{h^_ij are unitary. For a, 6, A 
{0, 1} and a partial transcript h?_ ly define unitaries A(a, 6, A) E £(C 2 ) and A^(/i^_ l5 a, 6, A) by 

A(a,6,A)= Yl \(b,x®A) B )((a,x) A \ 

xe{o,i} (5.9) 
Af (hf_^ a, 6, A) = Uf{hf_^ (A(a, 6, A) ® l)uf (hf.J , 

i.e., Af (/if_ 1; a, b, A) is A(a, b, A) acting on Bob's qubit for game (j,hj_i). 

Recall the distribution of the ideal CHSH game outcomes (A,B,X,Y) from Definition 5.3. 
Define a super- operator Gf by 

gf(\hj-u a,j, Xj^hj-t, aj, Xj\ <g> p) 

= £(Pr[(B,y) = (bj^KAX) = ( aj , Xj )} Ih^hj] ® (1® Af )p(l ® Aft)) , (5.10) 

where Af = Af (/if ,.«;./;,•..<•; Vj ). Let Qf B = gf o Sf, and for £>k, let gj? e = gf--.g B and 

g£F = g? b ---g£ b . Thus, 



qAB i )= i V f UU^[(B,Y) = (b j ,y j )\(A,X) = (a j ,x j )h 

w/iere Afj(hj) = A.f(hf_ 1 ,a,j,bj,Xj®yj) • • • Af (/if , a2, 62, ^2©2/2)Af (ai, 61, xi©yi). TT&is non-local 
super- operator has the effect of measuring Alice's qubits, guessing Bob's answers according to the 
appropriate ideal conditional distribution, and then applying a unitary to correct Bob's qubits. 
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In the above definition, it is worth remarking that the super-operator Gf guesses Bob's 
measurement result yj according to its distribution in the ideal CHSH game, and not according to 
its distribution in S. This type of approximation is inevitable because a super-operator that only 
measures Alice's qubits cannot precisely capture the transcript distribution's dependence on Bob's 
measurement outcomes for previous games. 

The super-operators Gf are useful because they do not affect the trace distance between matrices 
that are block-diagonal in the computational basis for transcripts: 

Claim 5.18. For any a = J2 h \h)(h\ ® a h , \\Gf (a)\\ tr = \\a\\ tr . 

Proof. Gf can be split into two super-operators: the first adds \bj,yj)(bj,yj\ to the transcript 
register, weighted by a certain probability; and the second applies a controlled isometry to the state 
register. Neither operation changes the trace norm. □ 

Observe that if S is an ideal strategy, projecting Alice's half of an EPR state onto \{cl,x)a) 
also collapses Bob's half to the same state |(a, x)a). A(a, b,x © y) corrects this to y)#). Hence 
Pj+i = £ff(pi) = Gij(pi). We next show that if most games are structured, then pj+\ is close to 
G\f(pi) in trace distance: 

Lemma 5.19. Let S be a (5, e) -structured strategy. Then for all j, 

\\££f(pi)-Gf,f( P i)\\ tI <j(26 + 0(V-e)) . (5.12) 
In particular, letting \ip(hf)) = Pi tj (hf)\il;)/\\P£ j (hf)\il;)\\ and g(\a)) = \a)(a\, 

E[||e(|^(ff i )»-e(Af i ,.(^ i )|^/)»|| tr ] <2n{25 + 0{Ve)) . (5.13) 
Proof. Using a hybrid argument, expand the difference pj+\ — Gff(pi) as 

phi ~ Gtf(Pi) = (phi ~ Gf B (Pj)) + Gf B { Pj - gftipj-i)) + ■■■ + G£!(P2 - Qt B (Pi)) ■ 

By a triangle inequality, and since applying a super-operator cannot increase the trace distance, 
\\pj+i ~ Gif (Pi)||tr - i max fce[j] \\pk+i ~ Qk B (pk)\\ tv - 
Next, expand ||p fc+ i - G k B (Pk) || tr as 

\\ Pk+l - Gi B (p k )\\ tv = £ ^{ H k-i = fcjk-ilH^jf (p(/uk-i)) - Gt B (p(hk-i))\\ tI ■ 

hk-i 

If game (fc, /i/c-i) is e-structured, then the total variation distance between the distribution of 
outcomes (a&, bk,Xk,yk) generated by £^£ B and the distribution generated by G^ B is at most O(e). 
Moreover, by Corollary 4.11, the resulting states are within 0{sje) in trace distance of each 
other. Therefore \\£^£ B (p(%-i)) ~ G^ B (p( h k-i))\\ tr = 0(y/e). On the other hand, the total 
contribution from terms for games that are not e-structured is at most 28. This implies 

\\pk+i ~ G£ B (Pk)\\ tr < 25 + 0(y/e), and yields Eq. (5.12). 

Applying Lemma 3.2 to Eq. (5.12) gives Eq. (5.13). □ 

We will use Lemma 5.19 four times below, in the proofs of single- and multi-qubit ideal strategy 
simulation, and local and global gluing (Theorems 5.9, 5.11, 5.28 and 5.12). It allows for turning 
weak simulation statements, i.e., bounds on \\£ff(pi) — £ff(pi)\\tr, into simulation statements, i.e., 
bounds on - £ij(pi)\\tv' 
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Corollary 5.20. There exists a contant n such that if S — (|^), {£f}, {£fY) ^ s an ^-structured 
strategy that is weakly S-simulated by S — {£f})> a strategy differing only in Alice's 

reflection operators, then S also ku k (5 + e) 1 ^ -simulates S. 

Proof The idea is that Lemma 5.19 allows for replacing Bob's measurement super-operators with 
an isometry. Since the isometry is the same for S as for 5, it can be removed without affecting the 
trace distance (Claim 5.18), and so S simulates S. Formally, we have 

ll^-(Pi) - ^(Pi)lltr = \\Gi,j£i,M) ~ GiJijlW by Claim 5.18 

= WGtfiPi) ~ Qtf (Pi)lltr since gfj = gfj 

< \\G£f(Pl) - £t! (Pl)lltr + WOlJ (Pi) - (Pl)lltr 
+ \\Sff(pi)-£ff( P l)\\tr ■ 

By Lemma 5.13, S is (e+ 16\/5)-structured, so Lemma 5.19 gives bounds for \\Qff(pi) — (pi)||tr 
and \\G£f(pi) - £££ (pi)||tr. Thus ||£^-(pi) - ^-(pi)||tr < /cn K ((5 + e) 1 ^ for a certain fixed con- 
stant k. Of course, ||£^(pi) — £^(pi)||tr = 0- D 



5.3.2 Second hypothetical protocol: Alice measures for Bob 

The super-operators Q^ B correspond to a hypothetical protocol in which Alice applies her measure- 
ments and then guesses Bob's measurement outcomes, after which Bob applies a unitary correction. 
A similar idea is that Alice could herself first apply Bob's measurement operators to her own qubits, 
collapsing both provers' qubits, and then she could either apply her own measurement operators or, 
equally well, simply guess a unitary correction. We next show that this second hypothetical protocol 
also accurately simulates the actual protocol. The applications of this claim (in Theorems 5.11 
and 5.28) are to show that Bob's measurement super-operators do not depend much on his local 
transcript — since Alice can apply them herself without even knowing his transcript. This is not 
a purpose that Lemma 5.19 can serve, since there the prover who measures is allowed arbitrary 
dependence on her local transcript. Nor does the claim replace Lemma 5.19. For our applications, 
it will be convenient to state the claim with the two provers switched from the above description, 
i.e., with Bob measuring for Alice. 

Definition 5.21. Let S be a strategy such that the operators U^{h^_-^) are unitary. Let F k {h k _^ a&, Xk) 

be the projection of Bob's qubit (fc, h k _^) according to Alice's ideal reflection R^ k , and let J^^ h j be 
the corresponding measurement super-operator. That is, letting g(\a)) = \a)(a\, 

F£{h%_i,a k ,x k ) = uZ{hU)\\(l + (-ir<) ® iK(^-i) 

^ h he(\hf +l ^ l ))®p) = \Y, (Q(\hf+i^«k,x k ))®F£ P F?) ■ (5 - 14) 

T , rABlhf c B\hf ^A\h^ 7 r AB\hf ^ABlhf ^AB\hf ™, 

Let J- k * 3 — c k 3 J~ k 3 and J~k i • -^-' iese super- operators capture the 

effects of playing Alice's ideal reflections on Bob's qubits before making Bob's own measurements. 

Observe that if S is an ideal strategy, then since a measurement on one half of an EPR state can 
be made equivalently on the other half, pj+\ = £^?(pi) — F^fipi). If most games are e-structured, 
then pj+i is close to Fffipi) in trace distance: 



33 



Lemma 5.22. Let S be a strategy and h £ a partial transcript such that for every j > £, Pi[game 
(j, Hj-i) is e-structured \H £ = h £ ] > 1 — 5. Then for all k > j > £, letting Pj(h £ ) — £f+i^ l _i(p{h £ )) , 

\\ef ht (Pj(h e )) -?f h * (Pi(M)IL < 0(y/e) + 45, and 

\KTk-Mhe)) -J$S? £tT/-M h ^L < (k-j)(0(y/i) + 4S) . (5.15) 
Proof. Let g(\a)) = \a)(a\. Then begin by placing an upper bound on 

|| Pi+1 (M -jfW (Pi(M)L = \\£t mt { Pj {hd) -Ff Blhf (Pi(h e ))h 

<\\£f h "(Pj(he))-^f hf (Pj(hi))\\ tr ■ 

Since pj(h £ ) — P r [^j-i = hj-i\Ht = h £ ]g(\h £ +ij-i))®p(hj-i), we can expand the right-hand 

side of this bound as 

\\£? K (Pj(he))-Ff lhf (Pj(he))\\ tI 
= J2 ^[Hj-i = hj-i\H e = h^jsf^ipih^)) - ^- 1 (p(Vi))| tr 

hj-! 

\ ^[Hj-i = h J-i\ H t = H Q{Pf(hf)\Hh 3 -i))) - QiFfrhf^a^XjMihj-!))) 



2 

hj — ]_ 5 ^ j v^ 1 2 



Now if game (j, /ij-i) is e-structured, then by Corollary 4.8, \\F^(h?_ v aj, Xj)\^j) — Pj 4 (/ij 1 )|'0j) || = 
0(y/e), so \\g(F^(hf_ v aj,Xj)\i/;j)) - g{Pf{hf)\^j))\\ tl = 0(^/e) (Claim 3.8). As aj and Xj are each 

summed over {0, 1}, it follows that \\p j+1 (h £ ) - jf 3 ^' (pj(h £ ))\\ ti < 0(y/e) + 45. 

Our claim now follows by a sequence of triangle inequalities in each step of which one of Alice's 
measurements is pulled over to Bob's side. Write 

Pk(h e )-rf*}f( Pj (he)) = (pk(h e )-^ B ^(Pk-i(he))) + (p*-i(M - T^f* (Pk-2(h e )j) 



By our above calculation, the trace norm of each term is at most 0(y/e) + 45. □ 

Corollary 5.23. Let S be a strategy and h £ a partial transcript such that for every j > t, Pi[game 
(j, Hj-\) is e-structured \H £ = h £ ] > 1 — 5. Then for all j > I, 

£f H rf+}%Mhz)) ~ ?f hf ?tS?-Mht))\ < (2(j -£)- l)(0(Vi) + 45) . (5.16) 

Proof. Let 5' = 0(y/e) + 45. By Lemma 5.22, \\£j lh " (pj( h e)) ~ Ff h ' (pj( h e))\\ tl < 5'. Also 

W^'^LMht)) - £? h H Pj (h e ))\\ tr and || Tf h * rf +1 f_Mh)) - jf h f ( Pi (/*))|L are both 

at most ||^ 4 ^'^i 1 (p(^)) — Pj(^)|| tl o which by Lemma 5.22 is at most (j—£— l)S f . Combining 
these bounds gives our claim. □ 

Measuring a qubit a second time does not change the trace distance. Therefore, as in Claim 5.18, 
for a single-qubit ideal strategy <S, we can replace T^ B with without affecting the trace distance: 
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Claim 5.24. Let S be a single-qubit ideal strategy. Then for any density matrices a and r, 

||^- 1 (---)|| tr = ||^- 1 (--r)|| tr • (5.17) 

Proof. Since 

j 7 AB\hj_ l = £ B\h ] _ 1 oJ7 A\h._^ appUcation of 

a super-operator cannot increase 
trace distance, ll^/^'^ -1 ( a — T ) || tr — H^ 7 /'^ -1 ( a ~ T ) || tr - The reason that this is an equality 

B\h B A\h B A\h B 

is that £■ 1 j ~ 1 measures the same qubit that T- j ~ 1 already measured. Since T- j ~ 1 stores 
its measurement result in a transcript register, no information is lost by measuring the qubit 

A\h B 

a second time or even discarding it. Slightly more formally, observe that T- — t) — 

\ Ea, I a J > X 3 )( a J i X j\® F f( h f- 1 , ^ , X J ) (a - T) F A (hf_ x , dj , X 



so 



CLj,Xj 

The expression F^{h B _ 11 aj 1 Xj){a — r)F A {h B _^aj^Xj) factors as the tensor product between a 
single-qubit state |(aj, Xj)^)((aj, xj)a\ and another matrix. The single-qubit state does not affect 
the trace distance, even after it is measured again 

5.4 Proof of Theorem 5.9: Simulation by single-qubit ideal strategies 

Proof of Theorem 5.9. By Proposition 5.16, we may assume without loss of generality that the 
isometries U®(h®_-±) from Definition 5.15 are actually unitary. Let S be the strategy with the same 
initial state |^) as 5, but that uses the reflections = U f( h f-i)H R a ® l)t/j 4 (/i^_ 1 ) for 

Alice. Then S is a single-qubit ideal strategy on Alice's side. 

Our proof that S closely simulates S is based on Lemma 5.19 and the following claim: 

Claim 5.25. For every j , \\£f B { Pj ) - £f B (Pj) ||tr = O (>/£)- 

Proof. Expand \\Sf B ( Pj ) - £f B ( Pj )\\tr = Prf^-i = fy-i] \\£f B (p(hj-i)) - £f B {p{h 3 ^))\\ tr . 

Split the sum according to whether game j is played with e-structure on transcript hj-\. The total 
contribution from unstructured games is at most 2Pr[game (j,Hj-i) is not e-structured] < 2e. On 
the other hand, by the CHSH rigidity lemma, Lemma 4.2, for any e-structured game, we have, using 
Claim 3.8 and letting g(\a)) = |a)(a|, 

upfWj)) - Q(pf B \^))\\tr < 2iip/ B i^) - pj AB m\ 

= \\(Rf®Rf-Rf®Rf)\iP j )\\ 
= 0(V~e) . 

Thus \\£f B ( Pj ) - £f B ( Pj )\\tr <2e + 0(V~e). □ 
From the expansion of S AB (pi) — S AB (pi) as 

(£f B { Pj ) - £f B ( Pj )) + ef ' - £f- B M-i)) + ■■■ + ££!(£f B (Pi) - £f B ( P i)) , 

it follows that \\££f(pi) - £~i B (pi)\\tr < jO{^e). Thus S weakly (nO( v / e))-simulates S. By 
Corollary 5.20, there is a constant k such that S xn x e 1 / x -simulates S. Since S is structured 
(Lemma 5.13), we can repeat the argument, but this time changing Bob's reflections, to get 
simulation by a single-qubit ideal strategy for both provers. □ 
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This completes the first part of the proof of Theorem 5.7. In the remainder of the proof, we will 
restrict consideration to single-qubit ideal strategies. This is okay since the strategy S is structured 
by Lemma 5.13. Furthermore, simulation is transitive; if we find a strategy S that 77-simulates <S, 
then S (ftn^e 1 /^ + ^-simulates S. 

5.5 Proof of Theorem 5.11: Simulation by multi-qubit ideal strategies 

Proof of Theorem 5.11. As in the proof of Theorem 5.9, it suffices to show that an isometric 
extension of S can be weakly simulated by a strategy S in which Alice plays according to a 
multi-qubit ideal strategy and Bob plays the same as in S. Indeed, Corollary 5.20 then turns weak 
simulation into a simulation statement. By Lemma 5.13, S is structured, so repeating the argument 
implies that Bob can also play according to a multi-qubit ideal strategy. 

Let us begin by defining Alice's strategy in S. Alice uses the Hilbert space (C 2 )® 71 ® T-La-> with 
the extra n qubits providing convenient workspace. The isometry X A : T-L a ^ (C 2 )® n ® T-La from 
Definition 5.6 simply prepends |0)® n . Thus the initial state for S is |0)® n ® Since S is a 
single-qubit ideal strategy (Definition 5.8), there exist unitaries L 7 j 4 (/i^_ 1 ) : %a — > C 2 ®T~L f A such 
that Riihf^) = Ufihf^iR* ® l)t/j 4 (/i^_ 1 ). In particular, we can fix a basis so U A = C 2 ® H' A . 
Number this qubit 0, and the other qubits from 1 to n. Then, in Definition 5.10, let y A be the 
identity, and define the operators M A {h A _^) by 

Mf = SrUf 

(5 18) 

Mf(hf_ 1 ) = S J Uf(hf_ 1 )Uf_ 1 (hf_ 1 )*V(a J - l ,x J - 1 ) . 

Here, the operators U A (h A _^) are understood to act on the %a register. Sk denotes the swap 
operator between qubit and qubit k. For a, x E {0, 1}, V(a, x) is a fixed one-qubit unitary that 
maps |0) to I (a, x)a)] the subscript in the expression above indicates that it acts on qubit 0. 
Since M A does not involve qubits 1 through j — 1 (nor qubits j + 1 through n), Eq. (5.18) defines a 
valid multi-qubit ideal strategy for Alice, using Eq. (5.6). 

Eq. (5.18) deserves some explanation. First of all, £ A and £ A act in exactly the same way: 
for any a e C(Ua), |0 n )(0 n | ® Sf(a) = £^(\0 n )(0 n \ ® a). They both expose a qubit, with Uf, 
measure that qubit, and then put it back, with . To understand notice that there is 

a trivial way of forcing a tensor-product structure for Alice's measurements: after a qubit has 
been measured, say as \(a,j,Xj)A), put that qubit to the side, rotate a fresh ancilla qubit |0) into 
\(dj,Xj)A), and continue playing using the ancilla in place of the measured qubit. This is how 
Mf works; t//_ 1 (/i/_ 1 )ty(a J _i, Xj -i) rotates the ancilla qubit to |( a j — 1 , x j — 1 

)a) and puts it into 

the place of the measured qubit for game j — 1, and SjU^(h A _^) exposes the qubit for the next 
game. Thus Eq. (5.6) seems to be the obvious way of defining a multi-qubit ideal strategy for Alice. 
It is not obvious, however, that S simulates S. The reason is that S does not just set measured 
qubits to the side — which would make simulation according to Definition 5.5 hopeless. It also tries 
to restore the qubits, by applying • • • . Our claim that S simulates S will boil down to 
showing that the qubit \(aj,Xj) A ) measured in game j will stay close to that through all later games 
(Lemma 5.26), and therefore when is applied it returns qubit j to its initial state |0). 

To prove Theorem 5.11, we need to bound || |0 n )(0 n | ® (pi) - £^ (|0 n )(0 n | ®pi)|| tr . By a 
hybrid argument, this is at most fcrnax^^j |||0 n )(0 n | ® £f B (pj) - £f B (\0 n )(0 n \ ® Pj)\\ tT > 
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At this point, we need to define some new notation. To save space, let us henceforth assume 
that the n prepended qubits have been incorporated into Alice's operators Therefore we will 
write simply p\ instead of |0 n )(0 n | ® p\ and Sf^(pi) instead of |0 n )(0 n | ® Sf^(pi). We aim to bound 
\\Sf B {p 3 )-Sf B { Pj )\\tr- Let ^ 

Tf(hf) = Ufihf^SjViaj, x s ) s Uf{hf_ x ) . (5.19) 

Then Eq. (5.6), R^hf^) = ■ ■ ■ Mf\R A )jM A ■ ■ ■ can be equivalently rewritten as 

Rt{hU)=T^...Tf\R*) j Tf...Tf , 

since T A ■ ■ ■ T A = U A ^V(cij, xj) M A ■ ■ ■ M A and the extra U A ^V(aj, Xj) factor cancels out. These 
T A {h A ) operators are more convenient to work with than the Mj 4 (/ij 1 _i) operators. (It is their 
dependence on Oj and Xj that disallows using them directly in the definition of <S.) Define super- 
operators Uf, Vj, Sj and Tj by, for a e £((C 2 )® n ® Ha), 

Uj(\h A )(h A \ ® a) = \h A )(h A \ ® Ufihf^aUfihf.^ 
Vj(\h A )(h A \0a) = Ih^l^Viaj^^aVia^Xj)] 
Sj{\h A )(h A \ <g> a) = \h A )(h A \ <g> SjoSj 
T j =U- 1 S j V j U j . 

Let Tj^k =Tk" - Tj+iTj and Vj^ = Vk ' * * Vj+iVj. Observe then that 

£f = T^SfTu-i . (5.21) 

Therefore, \\Sf B ( Pj ) - £f B ( Pj )\\tr = \\£f B Tij-i{ Pj ) - Tij-i£f B ( Pj )\\^ as T h being unitary, does 
not affect the trace norm. 

Next we claim that Tij-i(pj) ~ Vij-i(pj) and 7ij-i(pj+i) ~ Vij-i(pj+i), where by w we 
mean that the difference is at most xn^e 1 ^ (in trace norm) for some constant x. In other words, 
super-operator T, when applied to a ft, effectively only rotates the extra |0) qubits at the beginning 
of ft. If these approximations hold, then our theorem is proved: 

WS^Ttj-tipj) - Tij-iS^ip^l « ||£fXi-i(P.) " Vu-i^(Pi)L = , 

since fj 45 commutes with Vij-i- 

Both approximations are shown by a hybrid argument. For k < j, expand 

T 1>k ( Pj ) - V 1 , k ( Pj ) = T 2 , k (Ti(Pj) - Vi( Pi )) + T 3 , fc (T2Vi( Pi ) - Vi )2 (Pi)) 

+ 7i, fc (75Vi l2 (Pi) - Vi l3 (Pi)) + • • • + (T fc Vi, fc _i( Pi ) - V 1>k (j>j)) . 

For k ^ £, T k and commute. Thus, 



|7i,fc(Pi) - Vi,fc(pj)|| tr < fcmax \\Te(pj)- Ve(pj) 



Itr 



Our main lemma places a bound on ||7^(/9j) — ^(/°j)|| tr f° r £ < j- This means that later games do 
not much change qubits that have been measured earlier. 
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Lemma 5.26. There exists a constant x such that for £ < j , \\Tt{pj) — Vg(pj)|| t < rfe 1 ^. 

Proof. Since 5 is a single-qubit ideal strategy, Alice's measurement in game (j, /^-J projects her 
qubit for that game into exactly \{a,j,Xj)A). In particular, therefore 

Tr[((|0)(0|) ® (|0)(0|)^ ® 1) • V^H^+i)] = 1 . 

Recall from Definition 5.21 the super-operators ^f B - As these super-operators act on Kb, they 
commute with V^, St and ZY^, and do not change the above trace, so 

Tr[((|0)<0|) ® (|0)(0|), ® 1) • V.-^^Vi^+i)] = 1 • 
By Lemma 5.22, \\pj — Tf+ X j_i(pe+i)\\ti — 0(riy/e), and so by Lemma 3.7, 

Tr[((|0}(0|) ® (|0)(0|)^ ® 1) • V^WKPi)] > 1 ~ 0{ny/e) . 
Applying Corollary 3.5, there exists a state a = J2h A ® a h such that for r = (|0)(0|)o ® 

(|oxo|)<®(7, 

IIV^^WKPi) " r|| te < O(vWi) • 

(The state a is block diagonal because it is a partial trace of the block-diagonal matrix V^S^U^pj).) 
It remains only to substitute the definition Tt — U^SiViUi and apply two last triangle inequalities: 

11%) - V^-)|| tr = \\SeVeUe( Pj ) - V e U e (Pj)\\ tr < 0(v^e 1/4 ) + \\S e V e S e Ve(r) - V*S*V £ (r)|| tr . 
Since S^r = r, the final term is zero. □ 
This completes the proof of Theorem 5.11. □ 



5.6 Proof of Theorem 5.12: Gluing together multi-qubit ideal strategies 

Theorem 5.11 shows that Alice and Bob are close to playing according to a strategy in which every 
game uses a qubit in tensor product with the previous games' qubits. However, the qubit used can 
depend on previous games' outcomes. Next, in the third and last part of the proof of Theorem 5.7, we 
will argue that Alice and Bob must play using a single set of n qubits, fixed in advance independent 
of the transcript. The reason is essentially that the players cannot communicate with each other 
and their local transcripts are insufficiently correlated to coordinate a dynamic strategy. 

For a toy example of the issue, consider two provers who play the first n — 1 games honestly and 
who at the beginning of the last game share two EPR states, l^*)^ 2 . Say that for certain functions / 
and g, Alice uses EPR state f{h^_^) E {1, 2} in game n, and Bob uses pair gih^-i) £ {1? 2}. For 
game n to be structured, they need f{h^_ x ) = g{h^_^) so that they measure the same EPR state. 
Now Alice and Bob's local transcripts are each uniformly random, separately, but they have a 
constant correlation in every game coordinate. It is straightforward to argue based on coordinate 
influence that if Pr[/(i?^_ 1 ) ^ g{H^_^)\ is small, then / and g must both be nearly constant. In 
particular, although the majority function is the stablest balanced function [MOO10], it is not 
stable enough. Thus one of the two EPR states is used almost always. 

This example is of an essentially classical cheating strategy. The actual provers we face may be 
significantly more sophisticated. In particular, by cheating in small amounts in the first games, they 
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potentially can drastically change the underlying quantum state. For example, Alice might have 
knowingly managed to swap her halves of the two last EPR states along some transcripts h^_ x . 
Then she can use completely different strategies for the last game, depending on whether or not 
there has been a swap, without having to coordinate any classical information with Bob. There 
may also be much more sophisticated ways of cheating than this example. We worry especially that 
small amounts of cheating in earlier games might enable an avalanche of more and more blatant 
cheating in later games. 

Our "gluing" argument has two parts, that we term local and global gluing. In the local gluing 
argument, we show that most of the time, for two typical partial transcripts and h^' that differ 
in only one game coordinate j, the states created by Alice measuring along these transcripts are 
close to each other (up to unitary corrections on Alice and Bob's jth qubits). See Theorem 5.28 for 
a precise statement. Essentially, this means that Alice's strategy for games j + 1, . . . , n along 
does not depend much on game j. In the global gluing argument, we connect together all of the 
transcripts, by connecting far away transcripts with a sequence of local gluing steps. 

5.6.1 Local gluing 

Similar to Definition 5.17, we define unitary operators V(a, a', A) that rotate between Alice's 
different measurement bases (see Corollary 4.10): 

Definition 5.27. Let S be a strategy such that the operators JjP{hP_ij are unitary, for D E {A, B}. 

For a, a', A E {0, 1}, define unitaries V(a, a', A) <E £(C 2 ) and VP(hP_ v a, a', A) by 

y(a,a',A)= \(a',x@A) A )((a,x) A \ 

xe{o,i} (5.22) 

VPihf^ a, a', A) = Uf{hf_ x )^ (V(a, a', A) ® l) tff , 
i.e., VP{hP_^ a, a', A) is V(a, a', A) acting on the qubit in T~Ld for game (j,h®_^). 

Theorem 5.28. For cl^Xj E {0, 1} and a partial transcript hf, let hft r denote the same transcript 
except with the question and outcome for game j replaced by a 1 - and x'-. 

There exists a constant k such that, for p{n, 5, e) = nn K {8 + e) 1 ^, if S is a (5, e)- structured 
multi-qubit ideal strategy for n sequential CHSH games, then there is at least a 1— p(n, 5, e) probability 
that Hj lies in the set of hj that satisfy, for all a'- and x'-, 

<p(n,6,e) , (5.23) 

tr 

where VP = VP(hf_ v a' p aj, x 1 - Xj ). 

Proof. There are three parts to the proof. Corollary 4.10 begins the gluing: if game (j,hj-\) is 
6-structured, then HlVK^j)) — V-^\ip(hj')) || = 0(y/e). In trace distance, 

p{h 3 ) » Vfp(h/)VV . 

Since applying a super-operator cannot increase trace distance, therefore (p(hj)) is close 

to Vf-rf^j* (p(/i/))y/ t . In the second part of the proof, we use Corollary 5.23 of Lemma 5.22 
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to pull Alice's measurement super-operators back to her side, simultaneously eliminating Bob's 
measurements for games j + 1 and later; thus 



£fUMh 3 ))~v Hf^{ P {h>))vV 



This equation says that Alice's actions along the transcript h A have nearly the same effect as along 
the transcript hf f . It holds essentially because both super-operators can be pulled to Bob's side in 
the same way, if Bob also measures. In the third part of the proof, we apply Lemma 5.19. The 
lemma shows that p(hj) is close to p(h A ), up to certain unitary corrections on T~Lb- This allows us 
to eliminate Bob's measurement super-operators for games up to j, thus establishing the claim that 
£^+ik(p(hf)) is close to V J A £^^ j k (p(h A/ ))V J A ^ up to certain unitary corrections on Kb- These 
corrections are the same for the first j — 1 games, and since S is a multi-qubit ideal strategy they 
can be canceled out, leaving only a correction V? for game j. 

It will be convenient to establish the notation that for a vector |a), q{\o)) — \a)(a\. 

The next proposition combines the first two steps: 



Proposition 5.29. Under the conditions of Theorem 5.28, there is at least a 1 — \n5 probability 
that Hj lies in the set of hj satisfying, for all o!- and x'-, 

£?l%(p(hj)) ~ V^SWW^ < O(Ve) + MO(Ve) + 4 ■ 60V^S)(k - j). (5.24) 

Very roughly, this inequality means that Alice's actions in games j + 1 to k are almost the same 
starting with h A as starting with the perturbed transcript h A/ . 

Proof. By a union bound, Pr[all games are e-structured along H n ] > l — n5. By a Markov inequality, 
then, there is at least a 1 — \fn8 probability that Hj-i lies in the set S' = {hj-i : Pr[all games 
are e-structured along H n \Hj-i = hj-i] > 1 — VnS}. Let S = {hj : Vo^,^, Pr[all games are 
e-structured along H n \Hj — (hj-i,aj,Xj,bj,yj)] > 1 — 60VnS}. When game (j,hj-i) is structured, 
all outcomes occur with probability at least 1/60 (Corollary 4.7). Therefore any hj whose prefix 
hj-i lies in S f itself lies in S, so Pt[Hj e S] > 1 — \fn5. 

Now for hj E since game (j, hj-i) is structured, Corollary 4.10 gives || \ip(hj)) — V A \tp(h/)) || = 
0(y/e), where V A = V A {h A _^ a!-, <2j, x r -®Xj). Notice that since Bob's view along the two transcripts 
is the same, i.e., h? = h^ 1 and measurements on Bob's side commute with V^ 4 , we therefore have 

\\Ff^ (Pfa)) ~ V^fjipih/W^^ < \\gmhj))) - QiVfMh/)))^ = O(Ve), (5.25) 
using Claim 3.8. 

We complete the proof with an inductive argument that pulls Alice's measurement super-operators 
back over to her side and eliminates Bob's measurements in games j + 1 and later. 

Claim 5.30. For £e{j,..., k}, 

(5.26) 
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Proof. The proof is by induction in (k — £), starting with Eq. (5.25) for £ = k. 

Assume we are given Eq. (5.26) for some £ > j. By Claim 5.24, since the qubit has been 
measured already we can eliminate Bob's final measurement super-operator without affecting the 
trace distance: 

KiS^ MM) - V , A [^f+S^f+if MM))] V , A ' \\ K 



tr 



By Corollary 5.23, we can pull Alice's last measurement on Bob's side bac 
5' = 2n(O(^) + 4-60V^), (/>(/>;)) ~ sf K ^f+^-M^)) 

holds for the transcript h/ = (hf f , hf). Since applying £f!_i J k or £fl\ j k only decreases these trace 



<l to Alice's side: letting 
< 6 r . The same bound 



distances, therefore, 

<l hf rf + B $Mhj)) - Vf[£t^' Ff^MhMV^ < 0(V~e) + 2S'(k 
as claimed. □ 
In particular, letting £ = j in Claim 5.30, we obtain Eq. (5.24). □ 
Letting 5' = 2n(26 + 0(y/e)) and f(hj) = \\p(hj) - A^(/i j )p(^)A^(/i j ) t ||tr, by Lemma 5.19, 

6' 

E[/(i^)|game (j, Hj-i) is e-structured] < - — - < 6\l + 26) . 

Thus, given that game (j, Hj-i) is e-structured, there is at least a 1 — V^l + 25) probability that 
Hj-i lies in the set of hj-i with E[/(f/ J -)|fl J -_i = hj-{\ < ^8' (1 + 28). By Corollary 4.7, this 
implies that for all dj,Xj,bj,yj, f(hj) < 60y^'(l + 26). 

Combined with Proposition 5.29, there is at least a (1 — 8) (1 — y^^l + 26)) — y/nS probability 
that Hj lies in the set of hj satisfying, for all a r - and 

|Af J (^0^S^(^)) A ^(^) t " V J AA W^ 

< 0(y/e) + 4n 2 (0(^) + 4 • 60^5) + 2 • 60^(1 + 26) . 

So far, we have only used that S is a single-qubit ideal strategy. Since S is in fact a multi-qubit ideal 
strategy, there is a basis in which Af j(hj) and Afj(h/) are both tensor-products of j one-qubit 
unitaries, with the same unitaries on the first j — 1 coordinates. Removing these unitaries does not 
affect the trace distance in the above inequality and thus it is equivalent to 



£fl%(p(hf)) - V j A \f£f${p{h?))V j *Vfi\\ < p(n, 5, e) 



for some polynomial p(n, 5, e) that tends to zero with 5 and e, and Vf — Aj 5 ? (/i^_ 1 , aj, 6j, Xj © 
yj)^Af(hf_ v a f j,bj,Xj © yj). Finally, observe that for all x £ {0,1}, Vf maps \(a' j ,x)A) to 
\(aj, x © x j © x j)a), and so Vf — V?(hj_±, a^x 1 - © Xj), as claimed. This completes the proof of 
Theorem 5.28. □ 



Of course, a symmetrical statement to Theorem 5.28 holds also for Bob's super-operators. 
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5.6.2 Global gluing 

Our global gluing argument will fix a gluing target, a transcript h n . For partial transcripts h^, we 
consider the path A^ ) = X^\X^ 2 \ . . . , A^ = hk where A^ -1 ) and differ only possibly in 
the outcomes for game j. We will compare p(hf) to p(hf) by applying local gluing comparisons 
along each step of the path. (It is important that the coordinates be changed in increasing order, so 
that the unitary corrections for each comparison depend only on h n .) We will choose h n so that 
all local gluing steps along the path succeed, for most transcripts h^. Therefore, we will end up 
showing that the provers' strategy S is simulated by an ideal strategy in which they use the qubits 
defined by the fixed transcript h ni regardless of the observed transcript. 

Definition 5.31. Let S be a strategy such that the operators U^h^^) are unitary, for D E {A, B}. 

Similar to Definition 5.27, define unitary operators that rotate between Bob's different measurement 
bases: 



W(b,b',A)= \(b',y(BA) B ){(b,y) B \ 

ye{o,i} (5.27) 
WfQif^Ab', A) = Uf(hf_^(W(b,b',A) ® i)Uj> {hf_ x 



Furthermore, for notational brevity, define super- operators Vf B {h^a, a', A) andWf B (hj- U 6, 6', A) 
by 

Wf(/i H ,M , ,A)W = Wf B aWf B ^ , l * } 

where Vf* = Vf(hf_ v a, d \ A)V B (hf_ v a, a!, A) and Wf B = Wf(hf_ v a, a!, A)Wf(hf_ v a, a!, A). 

In the global gluing argument, we will need to handle various conditional probability distributions, 
such as the distribution of outcomes for game k 1 H^^ conditioned on Hj = hj for different values 
of j. Unfortunately, for some transcripts h n , these distributions can depend heavily on j, preventing 
us from coupling them together. This is a minor technical difficulty, not a serious obstacle. To get 
around it, we will move to the distribution H n of transcripts for n ideal CHSH games, in which 
each game is independent. This can be done at little cost if most games are structured: 

Lemma 5.32. IfPr[every game along H n is e- structured] Hj = hj] > 1 — 5, then the total variation 
distance between the distribution of H n conditioned on Hj = hj and the distribution of H n , from an 
ideal CBSB strategy, conditioned on Hj — hj, satisfies 

d TV (H n \Hj = hj, H n \Hj = hj) < 6 + 2 • 60ne . (5.29) 

Proof. Except for notational complications, the proof is the same whether or not we condition on a 
partial transcript hj. Therefore for simplicity assume j = 0. 

Let p{h n ) = Pr[H n = h n ] and v{h n ) = Pr[H n = h n \. Then drviv, v) = Y,h n ^(h n )>u(h n )(K h n) ~ 
v(h n )), which is at most S plus the same sum restricted further to transcripts h n along which all 
games are e-structured. If all games along h n are e-structured, then by definition p(h n ) < Y\j(pj + e), 
whereas v(h n ) — Y\jPji where pj — Pi[Hjj = hjj] > 1/60 (Corollary 4.7). Therefore, dTv{l^^) < 
5 + E hn MM (1 - Ili Pj/iPj + 0) < S + 1 - (1 - 2 • 60e) n < 8 + 2 • 60ne. □ 
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Lemma 5.33. If S is a (5, e)- structured multi-qubit ideal strategy for n sequential CHSH games, 
such that the operators U^h®^) are unitary, then for p(n, 5, e) the polynomial from Theorem 5.28, 
there is at least a 1 — 2n 2 p(n, 5, e) — 2n\fn5 probability that H n lies in the set 



h n : Vfc, min< 



r Pr[\\p(h£) - vtS {p{H))\\ tv < nV2p(n,8,e)}; 
\ Pr[||p(fcf ) - WtS (P(H? ))|| tr < W2p(M >£ )] . 



> 1 - rwS' 



(5.30) 



//ere V x A f = V^ B (/i fc _i, i fe , a fc , X k © x fe ) • • • V^ B (A 1} a u X x © xi) and 5' = ^2p(n,5, e) + (Vn8 + 2- 
60ne). 

Proof. By Theorem 5.28 and a union bound over j and fc, there is at least a 1 — n 2 p(n, 5, e) probability 
that H n lies in the set 

S, = : Vj,MX> llffiS^))- V /%>S'(^f ))lltr ^^ 5 ' e )} > 
with = Vf B (hj-i, a!^ x r - © Xj). By Lemma 3.2 and a Markov inequality, Si is a subset of 

S 2 = [h n : Vj,M-,4 Pr[||p(^) - V/ B (p(i/ fc A '))l|tr < > /2p(n,<J,e)|fl- j = hj] > l-y/2p(n,6,e)}. 



Furthermore, there is at least a 1 — nynd probability that H n lies in the set 

S3 = |fo n : Vj, Pr[Vz > j, game (z, Hi-\) is e-structured | i7j = /ij] > 1 — \/n<5 j . 
By Lemma 5.32, S3 is a subset of 

S 4 = {h n : Vj, d TV {H^\Hj = hj,H^\Hj = hj) < Vrt) + 2 • 60ne} . 

Taking the intersection of S2 and S4, we obtain that there is at least a 1 — n 2 p(n, 5, e) — ny/nS 
probability that H n lies in the set 

S 5 = {h n : Vj,k,a'j,x'j, Pr[||p(4 A ) - V/ B (p(i^'))|| tr < v^p(M^)|4" = M >!-<*'}• 

Let h n £ S5. Since the different game coordinates are independent of each other in the ideal 
distribution i/ n , we have 



Pr 



> 1-5' 



\p(hf,Hf +hk ) - Vf B (p(hf',Hf +hk ))\\ ti < V2p(n,8,e) 
without conditioning on Hj = hj . Since this holds for all a'j , x'j , in particular we find 

> 1 - 8' , 



Pr 



\p(hf,Hf +lfk ) - Vf B {p{hf_^H^ k ))l r < V2p(n, 5, e) 



where now \>f B — Vj(hj-i, Aj,aj,Xj © xj). By a union bound, 



j 
Pr 



Vj, \\p(hf,Hf +hk ) - Vf B (p(hf_ 1} H£ k ))\\ ti < V2 P (n,8,e) 



>l-n6' . 
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For i < j, let V AB = Vf B {hj-\, Aj, aj, Xj ®Xj) ■ ■ ■Vf B (h i - 1 ,A i ,ai,Xi®x i ). A triangle inequal- 
ity based on the expansion p(h£)-V$(p(H£)) = £ j6[fc] V^ k (p(hf, Hf +U ) - V?* pihf^, A£ k )) 
implies that 



Pr 



\\p(h£) - V^{ P {H))\\ tl < ny/2p{n^e) 



>l-nS' . 



This is one of the two bounds needed in the definition of 5, Eq. (5.30). Symmetrical arguments 
from Bob's perspective, and one final union bound, complete the proof of Lemma 5.33. □ 

Before proving Theorem 5.12, we need one last lemma, that characterizes the states at the 
beginning of each game along a structured transcript in a multi-qubit ideal strategy: 

Lemma 5.34. Fix a transcript h n along which every game is e-structured according to the multi- 
qubit ideal strategy S. For D e {A, B], let M D {h%) = (l (C 2)®(n-i) ® M^h^)) . . . M?y D . Then 
there exists a state \^ f ) such that for all k, 

M A M B \ip{h k )) — ®j e [ k ](\(aj,Xj)A)\(bj,yj)B)) <8> |^*)®( n_fe ) <g> |^')| < nO(y/e) . (5.31) 

Proof. Alice and Bob play each game k along h n according to the ideal CHSH game strat- 
egy on their fcth qubits. The state at the beginning of game (k + is M A M B \^(hk)) = 
(£)j£[k](\( a j i x j) A)\(bj i yj)B))®\i/Jk+i) f° r some state l^fe+i)- By the CHSH rigidity lemma, Lemma 4.2, 
there exists a state such that || 1^4+1 ) — <8> = 0(y/e). Since for sufficiently small e 
every outcome of the game occurs with probability at least 1/60 (Corollary 4.7), it follows too 
that - |^ +2 )|| = 0(V~e). Thus - ® |^ +2 )|| = 0(y/i). Chain together these 
inequalities for - |^>® (n - fc) K +1 >|| < nO{^e). □ 

Proof of Theorem 5.12. If h n belongs to the set S from Eq. (5.30), then 

5>r[i^ = h£]\\p(h£) - V^p(^)|| tr < n^2p(n,S,e) + 2nS' , 



h A 



where Vjjf = V^ B (hj-i, aj, aj,xj © xj) • • • Vf B (a\, a\,x\ © x\). Also, by Lemma 5.32, 

H^fc(Pi) " E Pr ^ = ^11^X^1 ®P( h k)\\ tI = 2d TV {HtH) < 2(n5 + 2 • 60ne) . 



Therefore, 

ll^fc(Pi) - E Pr ^ = ^PfcX^I ® ^fcP(^)|ltr ^ n v /2p(n,5,e) + 2n5' + 2(n8 + 2 • 60ne) . 

(5.32) 

Of course, a symmetrical bound holds from Bob's perspective. 

Therefore, to bound ||£^ fc (pi) - ^ fc (pi)||tr, and by symmetry \\£ B k (pi) - £ B k (pi)\\tr, in order 
to prove Theorem 5.12, we need only to bound the trace distance from £f k (pi) to ^ x [H k — 

h k]\ h k)( h k \ ® v i,kP( h k)- For this ' we wil1 a PP!y Lemmas 5.19 and 5.34. 

By Eq. (5.13) in Lemma 5.19 and a Markov inequality, there exists a constant x such that, for 
5" = v /2n(25 + xe 1 /2) 5 

Pr[||^(|^)})-^(A^(i? fc )|^)))|| tr <^] >1-S" . 
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Therefore, if we let 

Vfc, game (k,h k -i) is e-structured, \\g(\ip(h k ))) - g(Af k {h k )\^{h^))) || tr < 5", 



h n : 



and the symmetrical bound from Bob's perspective holds 



then by a union bound, Pr[H n G T] > 1 — nS — 2n5" . 

Assume that h n G T. For D G {A^}, let M D = M D (h%) be the operators defined by 
Lemma 5.34. Let the initial state for S be |^) = M A tM B t|^*)^ ® |^'). Then by Definition 5.17 
for Af k (hk), a triangle inequality, and Lemma 5.34, 



\ e {Mh£))) - e (mt))) i 



tr 



tr 



tr 



ie[fc] 

ie[fc] 

< \\q(MH))) - Q(A?, k (h k )^(h k )))\\ ti 
<<J' + nO(^) . 

Since for any transcript V^efl^))) = ^(M^ M B t (g) .^(K^-, x j ) A }|(a ij ^a})^*)^"-^'}) = 
it follows that ||ViJfe(M/#)>) - e(|^)»|| tr < nnO(^). Thus, 



tr 



tr z — r 



Itr 



<5' + nO(^) • 



(5.33) 



Putting together Eqs. (5.32) and (5.33), we obtain that £? k {pi) ~ ^ffc(Pi) for L> G {-4,5} 



provided that h n £ S DT. This completes the proof of Theorem 5.12. 



□ 



5.7 Converse to Tsirelson's inequality based on observed correlations 

By combining Theorem 5.7 and some simple statistics, we can extend Lemma 4.2 to obtain a 
converse to Tsirelson's inequality that depends on the observed correlations in a repeated game — 
Theorem 5.38 below. As a consequence, we will also derive efficient "self-testing" for sequential 
CHSH games, in Theorem 5.41 below. 

Let Alice and Bob be the two entangled provers playing n CHSH games, in sequence, with 
independent questions refereed by the verifier Eve. Let W — \{j G [n] : AjBj = Xj © Yj}\ be the 
number of games that Alice and Bob win. If Alice and Bob use an ideal strategy, i.e., a O-structured 
strategy, for all games, then by Hoeffding's inequality they are likely to win nearly cos 2 (7r/8)n 
games: 

Lemma 5.35. If Alice and Bob use an ideal strategy for n sequential CHSH games, then 

Yt[W > (cosV/8) - S)n] > 1 - e~ 2s2n . (5.34) 
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Conversely, let S be the number of games in which the provers' joint strategies are e-structured. 
We first claim that with high probability, either nearly all games are e-structured or Alice and Bob 
win significantly fewer than cos 2 (7r/8)n games. This lemma is a warm-up to Theorem 5.38 below. 

Lemma 5.36. Let e, 77 > and S < 776/8. Then 

Pt[W > (cos 2 (^/8) - S)n and S < (1 - 77)71] < e - 2n ^/*- d ) 2 . (5.35) 

Proof. Let Si, S2, • • • 3 S n and Wi, W2, • • • ? be 0/1-valued random variables, Sj being an indicator 
for whether the jth game is played in an e-structured fashion, and Wj an indicator for Aj A Bj = 
Xj © Yj, i.e., for the provers winning the jth game. Then S = J2j $j an d ^ = Let 
p cos 2 (7r/8) and e' e/8. We know 

Pr[W} = = 1] < p Pr[Wj = l\Sj = 0] < p - e' . 

Let Ti, . . . , Y n be independent Bernoulli(p) random variables, and Ai, . . . , A n be independent 
Bernoulli (p — e f ) random variables. Couple Wj for the first structured game to Ti such that Wj < Ti, 
for the second structured game to T2, and so on. Similarly, couple Wj for the first unstructured 
game to A n such that Wj < A n , for the second unstructured game to A n _i, and so on. This yields 
the bound 

Pt[W> (p-S)n, S < (l-r?)n] <Pr[j2 T i + J2 A i - (P ~ 6 ^ S < i 1 ~ vh 

3<S j>S 

<Pr[ E A,->(p-(5)n 

i<(l-^)n j>(l-ry)n 

Let X = X!j<(i-77)n r j + Z)j> (1-77)71 A/ and ^ = E W = (P ~ r?e ; )n. Hoeffding's inequality implies 
that if S < rye 7 , then Pr[X > (p - <5)rc] < exp(-2n(r/e / - 5) 2 ). □ 

This lemma can be seen as a weak converse to Tsirelson's inequality based on the observed 
correlations for a sequence of CHSH games. It says that if the provers do not use a structured 
strategy most of the time, then they are unlikely to win too many games. Our goal, though, is to 
prove a stronger statement, based on Theorem 5.7: If the provers do not use a nearly ideal strategy 
for most subsequences of games, then they are unlikely to win too many games. The logic behind 
this claim will be essentially the same as that behind Lemma 5.36. 

Definition 5.37. For e > 0, call a strategy S for n sequential CHSH games e-ideal if an isometric 
extension of S is e-simulated by an ideal strategy. S is e-ideal with respect to the isometries 
X D : H D (C 2 )® n ® H' D , for D E {A,B} 7 if the isometric extension of S by X A and X B is 
e-simulated by an ideal strategy. 

In particular, if S is e-ideal with respect to X A and X B , then for \ip) E H,a®^b®^c the initial 
state, there exists a state \ip f ) E H' A ® T~L f B ® He such that, letting g(\a)) = \a)(a\ and p\ = ^(1^)), 
p x = g (\tf;*)® n <g> |^')) and X AB (p) = (X A ® X B )p(X A ® X B )\ 

\\X AB { P1 ) -pi|| tr < e and \\X AB S° n ( Pl ) - ^n(Pi)|| tr < 2e (5.36) 

for D E {A,B}. Here, is the measurement super-operator for prover D, and £® n is the ideal 
measurement super-operator that uses the jth qubit in game j of the set (Definition 5.1). 
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Theorem 5.38. Let Alice and Bob play in sequence N sets each of n sequential CHSH games. Let 
W < Nn be the total number of games that Alice and Bob win. Fix e > 0, and let G < N be the 
number of sets of games for which the provers ; joint strategy for that set, conditioned on the previous 
games' outcomes, is K*n K * e 1 / K * -ideal, where is the constant from Theorem 5.7. Let 77 > 0. Then 
for any S such that t = ^e 2 r]N — SNn > 0, 

Pt[W > (cos 2 (tt/8) - 6)Nn and G < (1 - rj)N] < exp(-t 2 /(2Nn)) . (5.37) 

Proof. For j E [Nn], let Wj = 1 if Xj A Yj = Aj © Bj, i.e., if the provers win game j, and let Wj = 
otherwise. Let Sj be the indicator variable for game j being e-structured. For k E [n], let Gk = 1 if 
after k — 1 sets of games, the provers' strategy for the next set is e-ideal, and let Gk = otherwise. 
Then W = EjelNn] Wj and G = J2ke[n] G k . ' 

For k E [iV], let be the indicator variable for the fcth set of games being e-structured 
(Definition 5.2). By the contrapositive to Theorem 5.7, if Gk = then the strategy for the fcth 
set of games cannot be e-structured, so Hk = also. That is, Hk < Gk, so letting H = ^2 k Hk, 
Pr[W > (cos 2 (tt/8) - S)Nn 1 G < (1 - r))N] < Pr[W > (cos 2 (^/8) - S)Nn 1 H < (1 - r])N}. 

Let p = cos 2 (7r/8) and e' — e/8. Let Ti, . . . , Tnui Ai, . . . , A^vn be independent random variables, 
with Tj rsj Bernoulli (p) and Aj ~ Bernoulli (p — e r ). Let Ti, . . . , T/v n be Bernoulli(l — e) random 
variables. As in the proof of Lemma 5.36, the idea now is to design an appropriate coupling from 
the Wj to these simpler random variables. 

For k E [iV], let c(fe) = {(fc — Y)n + 1, . . . , kn} be the set of games in the kth set. If Hk = 1, 
then let J/e = fcn. If — 0, then let Jk be the largest index j E for which the probability that 
game j is e-structured is less than 1 — e. By Definition 5.2, such an index exists, so Jk is well-defined. 

Define the coupling as follows. First, for j E and fc E [iV], couple Wj to a random variable 
Sj such that VFj < Sj and 

Ti r . + (1 _ Tj)Aj if H k = 0, j = J fc and fe - Ek><k H k> < \vN] 
otherwise . 

In the case Hk — and j = this coupling can be achieved by first coupling Sj < Tj. Note 
that although the T and A variables are fully independent, the Tj variables are not necessarily 
independent of each other or of the T and A variables. Call a random variable Sj unstructured if it 
has the form TjVj + (1 — Tj)Aj. The condition k — J2k'<k ^h' < \vN] ensures that we couple at 
most [77 N~\ Wj variables to unstructured Sj. 

The Sj variables have a Markov structure that we will use to define a martingale. Before 
doing so, we need to make use of the condition H < (1 — rj)N. To this purpose, we next define 
a set of random variables {Sj}, such that exactly \r]N] of them are unstructured. For all j such 
that Sj is unstructured, let Ej = Sj be unstructured as well. If N — H > \r]N] , then no more 
unstructured variables are needed; let Sj = Sj = Tj for all remaining j. Otherwise, we are still 
missing \r]N] — (N — H) unstructured variables. Work backward starting with j — Nn, setting S^- 
to be unstructured so long as the total number of unstructured Sj is less than \rjN~\ . For all 
remaining j, let S^- = Sj = Tj. Under this construction, notice that Sj = Sj for all of the initial 
games, certainly for all j E s(k) with k < N — \rjN/n\. Because we set the additional unstructured 
variable starting from the end, the variables Sj still form a Markov sequence. (This would not have 
been the case had we started with j = 1 because H is not then determined.) 
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In general, it need not hold that < ^2jE'-. If H < (1 — rj)N, though, then indeed 

J2j Wj < J2j smce m this case E'- Ej for all j. Therefore, letting E f J2j 

Pr[W > (p - S)Nn, H < (1 - rj)N] < Pr [3' > (p - 5)7Vn] . 

We will bound this probability using Azuma's inequality for martingales. The sequence of variables 
Ilj — ^ < ^ (S^ — E [E'i | E' ± , . . . , S^-J) form a martingale, with |IIj — IIj_i| < 1. By Azuma's inequality, 
therefore, for any t > 0, 

e -*wn) > Pv[UNn > t] = Pv [ E >> t + Ej Eiajisi, . . . , s^]] . 

By construction, there are always [77 N~\ unstructured variables Ej, meaning that with probability one, 
E.E^IS;,...,^;.^]] = (Nn- \7jN])p+ \r]N]((l-e)p + e(p-e")) = pNn - ee f \r]N]. Therefore 
set t = ee f \rjN] - SNn > \e 2 r]N - SNn to conclude the proof. □ 

Typical values for the parameters in Theorem 5.38 are S ~ 1/y/Nn and e 2 r] ~ y/n/N. There IS 
of course some freedom in choosing the parameters' exact values. To simplify later applications, 
though, we will restate Theorem 5.38 with particular parameter choices, and in a more easily applied 
form. We make no attempt to optimize the parameters. 

Theorem 5.39. Let ft* > 1 be the constant from Theorem 5.7. For a > 16/^1 and n > 100, 
let Alice and Bob play in sequence N > n a_1 sets each of n sequential CHSH games. Let W — 
\{j E [Nn] : AjBj = Xj © Yj}\ be the total number of games that Alice and Bob win. Say that Eve 
accepts at the end of the protocol if 

W > cos 2 (7r/8)7Vn - ^^Nn\og(Nn) . (5.38) 

This protocol satisfies the following completeness and soundness conditions: 
Completeness: If Alice and Bob play using an ideal strategy for all Nn games, then 

Pr[Eve accepts] > 1 \-r . (5.39) 

Soundness: Assume that Pr[Eve accepts] > 1 — e. Let ( = n - a /( 32K *) . Then for K E [N] chosen 
uniformly at random, the probability that after (K — l)n games the provers 7 strategy for the 
Kth set of n games is (-ideal satisfies 

Pr[Kth set of games has (-ideal strategy] > 1 - e - n~ a/8 . (5.40) 

Proof. The completeness condition follows by Lemma 5.35. Therefore, we will only argue soundness. 

Apply Theorem 5.38 with parameters 8 — k^J\og(Nn) j (Nn), n — 24k^/\og(Nn)n/ (Nn) 1 / 4 
and e' = l/(Nn) 1 ^ 8 , with k = 1/(2^2). Then t := \e' 2 nN - SNn = 2ky / Nnlog(Nn) > 0. Let 
£ = K*n re *e /1 / K *. We obtain that, for G being the number of £-ideal sets of games, 

Pr[ifth set is £-ideal] > (1 - n) Pr[G > (1 - n)N\ 

> (1 — 7/)(Pr[Eve accepts] — Pr[Eve accepts, G < (1 — n)N}) 
>l-e-n- exp(-t 2 /(2Nn)) 

> 1 - e - lQ^J\^jjfn)n/(Nn) l/A . 
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Finally, 10 v /log(iVn)n/(iVn) 1 / 4 < 10y/a logn/n a / 4_1 , which is at most n~ a / 8 for a > 16 and n > 85. 
Since a > 16ft 2 , £ = ^^/(TVn) 1 /^*) < ^n~ a ^ 16 ^\ which is at most n -«/(32**) for Q > 16/c 2 
and n > 3. □ 

The sequential CHSH game theorems assume that there are only two provers, Alice and Bob. 
This setting holds for the applications to device-independent quantum key distribution and blind, 
verified computation. However, to show that QMIP = MIP*, in Theorem 7.2 below, we will need 
Alice to share entanglement with multiple provers, say £>i, ... , Bp. Theorem 5.39 still applies, if 
we group Si, . . . , B^ together into a conglomerate prover, but we need to ensure that it respects 
the tensor-product decomposition of T-Lb-i ® • • • <8> T~Lb £ - This is straightforward to see for sequential 
CHSH games, since only one of the steps in the proof of Theorem 5.7 involves operations that can 
cross between T-Lbj spaces: the truncation to finitely many dimensions (Lemma 5.14). By separately 
truncating the spaces %b 1 ^ • • • ,Hb £ i i.e., applying Lemma 5.14 in £ steps, we obtain that the ideal 
strategy S that closely simulates the provers' strategy S obeys the same locality constraints as S: 

Proposition 5.40. If "Bob" is actually a collection of separate provers Si, ... , B^, where Bj plays 
on T-Lbj Tij out of every set of n CHSH games, then in the conclusions of Theorems 5.7 and 5.39, 
we may assume that the isometry X B : Hbx ® • • • ® T~Lb £ c_ ^ (C 2 )^ 72 ® H f B , with respect to which the 
provers' strategy is (-ideal, factors as the tensor product of isometries X B i : Hbj ^ (C 2 )^ ®7~l! B . . 

In the "self-testing" framework [MY04, DMMSOO, MMMO06], one is allowed to reinitialize and 
run the same experiment multiple times in order to test its functionality. By substituting the right 
parameter values into Theorem 5.38, we obtain as a corollary efficient self-testing for sequential 
CHSH games: 

Theorem 5.41 (Self-testing sequential CHSH games). Let S be an arbitrary strategy for n sequential 
CHSH games. Let e > be at most a sufficiently small constant. Let k > and let n* > 
solve n* /log n* = 256/c 2 (4ft 2 + 3)ft^*/e 4 ^% where ft* is the constant from Theorem 5.7. Let 
N= (max{n,n*}) 4 **+ 2 . 

Consider running the strategy S N times, reinitializing the joint state of the provers and the 
environment between sets. Let W < Nn be the total number of games that Alice and Bob win. 
Let 5 = k^log(Nn)/(Nn) and p = cos 2 (tt/8). 

• If S is an ideal strategy, then 

Pt[W > (p - 5)Nn] > 1 - n - 2fc2 (^*+ 3 ) . (5.41) 

• If S is not e-ideal, then 

Pt[W > (p - S)Nn] < n -^ 2 (4^+3)/2 ( 5>42) 

Proof. For S ideal, the claim follows by Lemma 5.35. 

Consider next the case that S is not e-ideal. Let e r = (e/(ft*n^*))^* , where ft* is the constant 
from Theorem 5.7; thus e = ft» t n^*e /1 /^* . By Theorem 5.38 with parameter 77 tending to one, 
Pt[W > (p - S)Nn] < exp(-t 2 /(27Vn)), so long as t = \e f2 N - SNn > 0. Assume that n > n*. 
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Substituting our parameter choices for N and S gives 




*V( 4 ^* + 3 ) lo S n 



> \/iVnfc \/( 4 ^* + 3) log n , 



where the inequalities follow by using the definition of n* to bound the bracketed expressions. 
In particular, t > 0, so the bound from Theorem 5.38 indeed holds. It follows, too, that 



exp(-t 2 /(27Vn)) < n -^ 2 (4^+3)/2 = 



-k 2 /2 



If n < n*, then the same inequalities all hold using n* in place of n everywhere. 



inequalities are exp(— t 2 /(2Nn)) < (n* 



-fc 2 (4/,2+3)/2 



< n 



-/c 2 (4^ + 3)/2 



The final 

□ 



By repeating the N experiments in Theorem 5.41 and taking the majority of the test results 

? 

W > (p — 5)Nn, the completeness and soundness parameters in Eqs. (5.41) and (5.42) can efficiently 
be made exponentially close to one and exponentially close to zero, respectively. 

Along with other self-testing problems, Magniez et al. have previously studied self-testing for 
sequential CHSH games [MMMO06, Corollary 3]. Their result for sequential CHSH games is weaker 
than Theorem 5.41 in two aspects. First, they assume a fixed tensor-product structure for the 
provers' measurement operators for different games, whereas we derive this structure. More precisely, 
they assume that the Hilbert space for prover D is divided as Hd = Hp ® • • • ® an( ^ ^hat tne 
measurements for game j act only on H J D . Second, their analysis requires an overhead exponential 
in n, whereas the overhead in Theorem 5.41 is polynomial. 



6 Tomography 

Theorem 5.7 lets us test two entangled provers to gain confidence that they really do have a 
state close to n shared EPR states that they nearly honestly measure one at a time in sequential 
CHSH games. Even though the CHSH game is very simple, it is practically useful in quantum 
key distribution for extracting shared randomness that is guaranteed to be uncorrelated with any 
outside environment. Theorem 5.7 may also have other applications in cryptography; CHSH games 
are also used, for example, in randomness expansion [PAM+10, AMP12, PM11, FGS11, VV12]. 

In this section, however, we will leverage the sequential CHSH game test to build tests for more 
complicated multi-qubit operations. Given single-qubit measurements, the natural approach to test 
more complicated operations is to apply tomography. We will therefore consider protocols in which 
one prover is asked to apply the single-qubit measurements of sequential CHSH games and the other 
prover is asked either to play sequential CHSH games, or to apply certain multi-qubit operations. 
Success in the CHSH games assures us that the first prover is playing nearly honestly, which means 
that her measurement results give meaningful statistics for tomographically characterizing the 
multi-qubit operations of the second prover. 

In the state tomography problem, one is given n copies of an unknown state p E C(H), and 
can measure the states to roughly determine p. State certification is a promise, decision version 
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of tomography. In state certification, one is given the additional promise that for a fixed state a, 
either p — a or p is far from <r, and the goal is to determine which situation holds. This model is 
insufficiently adversarial for our applications. We allow the weaker promise, that for an arbitrary 
n-system state p E £(11®™), either p = a® n or there is a significant probability that its reduced 
density matrix on a random subsystem is far from a. 

Despite the power of Theorem 5.7, the tomography arguments are still surprisingly involved. 
There are three essential problems: 

1. Characterizing tomographically an n-qubit state generally requires collecting statistics on 4 n 
separate observables, using exponentially many copies of the state [NCOO]. Tomography 
is more efficient on restricted classes of quantum states. Compressed sensing techniques 
allow low-rank states to be recovered with fewer experiments [GLF+10, Liull, Groll]. For 
example, an n-qubit pure state can be characterized with only 0(2 n ) different experiments. 
An n-qubit matrix-product state with rank r can be characterized with only 0{nr 2 ) different 
experiments [CPF+10]. (These procedures also detect if the actual state is far from being 
pure or far from a rank-r matrix-product state.) The task of certifying a state instead of 
tomographically characterizing it is still more efficient. The fidelity of a state a with a known 
pure state can be estimated with only a constant number of different experiments, although 
still requiring a polynomial number of copies of a [FLU, SLP11]. 

Our setting is not compatible with this tomography and certification framework. For example, 
we would like a test Eve can apply to gain confidence that, when she asks him to, Bob indeed 
applies a Bell basis measurement to two of his shared EPR states. 4 This operation involves 
only a constant number of qubits, but Eve might want Bob to apply it many times and 
there is no guarantee that the operations he actually applies are identical or even decided 
on non-adaptively. The process being characterized therefore involves many qubits. An 
exponential or even polynomial overhead is unacceptable — in fact, Eve can only ask Alice to 
make her CHSH game measurements on one n-qubit state. 

This setting is therefore more adversarial than standard tomography, in which it is generally 
assumed that the same state can be prepared repeatedly. The problem is similar to one we 
faced in the analysis of sequential CHSH games: we need to allow the adversary memory. 

2. A second problem is that we want to characterize the operations the provers apply to their 
shared EPR states, and not just the states that these operations create on the other side. The 
distinction is the same as that between process and state tomography. 

This difference will turn out to be surprisingly important in our analysis. We are be able 
to analyze state tomography for a broad class of states, and process tomography only for 
a very limited class of operations. The protocol used for process tomography will also be 
more involved than that for state tomography, using some additional sequential CHSH games. 
Essentially, the problem is that the correct states could be generated by incorrect processes. 
For example, statistical tests are not sufficient to catch Bob cheating in just one of the many 
operations he is asked to apply. In particular, he might cheat in the first requested operation, 
and instead of a Bell pair measurement might cyclically shift all of his EPR state halves. If 
he subsequently plays honestly except taking this shift into account, then he can never be 
caught even though his overall strategy is highly dishonest — for example, when Eve asks him 

4 The Bell basis consists of the four orthonormal states -4 (|00) ± |11)) and -4(101) ± |10)). 
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to apply a Bell measurement to his third and fourth qubits, he instead applies it to the fourth 
and fifth qubits. 

To avoid this problem, we will need to apply stronger tests that let us be sure that Bob cannot 
cheat in even one of the operations. A Bell pair measurement is a stabilizer operation [NCOO]. 
This allows Eve to reject if even a single experiment has an incorrect measurement outcome, 
instead of having to collect statistics on many experiments. 

This example suggests that perhaps we should use a weaker definition of process tomography, 
because Eve only cares that Bob applies a Bell measurement to two qubits that are maximally 
entangled with Alice's third and fourth qubits, and she does not care where in Bob's Hilbert 
space these qubits are kept. Intuitively, it does not seem very reasonable for process tomography 
to be restricted to stabilizer operations, but this is the best analysis we have so far been able 
to apply. 

3. A third problem is that saturating Tsirelson's inequality for the CHSH game only implies 
that Alice is honestly making X and Z measurements on her half of a shared EPR state. For 
tomography, however, we also need measurements in the Pauli Y basis. There is a technical 
solution that allows us to add Y operators to the game. Instead, though, we will use a theory 
developed by McKague [McKlO], that shows the existence of a large class of states that are 
fully determined by only X and Z measurements. 

We explain McKague's theory of states determined by X and Z measurements in Section 6.1 
immediately below. In Section 6.2, we study state tomography for states that are determined by X 
and Z measurements. In Section 6.3, we study process tomography, specializing our discussion to 
commuting sets of X and Z Pauli stabilizer measurements. 

6.1 States fully determined by tomography in the X and Z bases 

In the standard CHSH games that we have chosen to analyze, each prover has only two measurement 
settings, that in the honest strategy may be identified with X and Z operators. For carrying out 
tomography, however, it is generally necessary to be able to measure in the Y basis as well. 

One option we have, therefore, is to extend the CHSH game to add Y operators. The y direction 
in the Bloch sphere can be fixed, up to a sign, by adding measurement directions intermediate 
between the x and y axes in the Bloch sphere, and intermediate between the z and y axes. See 
Appendix A. It is not possible to fix the sign of the Y operator, since a prover who consistently 
measures using — Y will give indistinguishable statistics from one who uses +Y. To force the provers 
to use the same choice of sign consistently, the verifier can ask one of the provers to measure 
random pairs of qubits in the Bell basis. Intuitively, this will force the other prover to use the 
same sign choice for every qubit, since \{I ® I + X ® X + Z ® Z — Y ®Y) is a valid state but 
| (/ ® I + X ® X + Z ® Z + Y ®Y) is not. This approach is somewhat complicated, though, because 
it adds another step to the protocol. 

A simpler approach, that we follow here, is to argue that for certain states, reliable tomography 
can be accomplished without needing to measure in the Y basis. This observation is due to 
McKague [McKlO] and was suggested earlier by Magniez et al. [MMMO06] . McKague shows that 
for |^*) = ^(|00) + |11)), an EPR state, the states (J® T)|^*), for any single-qubit real unitary T, 

and CNOT24|V 7 *)i2 ® as we ^ as finite tensor products of these states, are exactly determined 

by their traces against tensor products of /, X and Z operators. That is, they are determined by 
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the expectations of observables that can be estimated using measurements in the X and Z bases. 
We call such states "XZ-determined." 

In this section, we give simplified proofs that a much larger class of states is XZ-determined. 
However, characterizing the full set of XZ-determined states remains an open problem. 

Definition 6.1. For a Hilbert space %, a set of operators S C C(%) and d > 0, a state a E C(%) 
is determined by S with exponent d if there exists c > such that for all e > and any state 
P G C(U), 

max|TrP(/9-<7)| < e =► \\p - a\\ tl < ce d . (6.1) 

P^S 

The state a is determined by S if there exists d > such that a is determined by S with exponent d. 

For % — (C 2 )® n , a state a is XZ-determined (with exponent d) if it is determined (with 
exponent d) by the Pauli operators {/, X, Z}® 71 . 

Both definitions extend to pure states E H by setting a = I^X^I- 

By basic algebraic geometry, robustness follows from the e = case: 

Lemma 6.2. For a finite- dimensional Hilbert space %, a state a E is determined by a finite 

set S C jC(H) if and only if for any state p E C(H), the implication of Eq. (6.1) holds at e = 0. 

Proof By Sylvester's criterion, the set of states in % is a compact, semi-algebraic set. The 
functions f{p) — maxp G ^ |Tr P(p — a)\ and g(p) = \\p — cr\\ Fl where || • \\ F is the Frobenius norm, 
are continuous, semi-algebraic functions. If f(p) — implies g{p) — for all states p, therefore 
by Lojasiewicz's inequality [BR90, Prop. 2.3.11] there exist c > and an integer d > 1 such that 
g\p) < cf{p) 1 / d for all states p. □ 

Lemma 6.3. The following are examples of tomographically determined states: 

1. Any n-qubit state a is determined with exponent 1 by the Pauli operators {/, X, y, Z}® n . 

2. The set of one-qubit XZ -determined states is exactly + cos(#)X + sin(#)Z) : 9 E [0, 27r)} ; 
i.e., the set of pure states in the xz-plane of the Bloch sphere. 

3. There exist two-qubit mixed states that are XZ -determined. In particular, the state ^|0)(0| ® 
l+X+l + ll+X+l ® |0)(0|, where |+) = -L(|0) + |1)) ; is XZ -determined with exponent 1/4. 

Proof sketch. Any operator p E £((C 2 )® n ) can be expanded in the Pauli basis as p = ^ Ylp^v Pp^i 
where V = {/, X, Y, Z}® n and p P = Tr(pP). Since for P E V, ||P|| t r = 2 n , by a triangle inequality, 

llPlltr < ]n E H^ P lltr = E 1^1 ' ( 6 ' 2 ) 

Per Per 

Furthermore, if p is a state, then ^ SpgP Pp ~ ^ r (P 2 ) — ^? with equality if p is a pure state. 

1. If for a state p and for all PgP, \pp — op| < e, then by Eq. (6.2), \\p — cr\\ tT < 4 n e. 

2. Similar calculations show that all of the one-qubit states {^(1 + cos(#)X + sin(#)Z)} are 
all XZ-determined. These are the only one-qubit, XZ-determined states since any state of the 
form \{I + xX + yY + zZ), with x 2 + y 2 + z 2 < 1, has the same X and Z Pauli coefficients as 
\(I + xX + zZ). 
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3. Let a = ^(|0+)(0+| + |+0)(+0|). If p is a state with the same Z}® 2 coordinates as a, 

then i(p + SWAPpSWAP 1 ") is a state of the form a + Epe{/,x,y,z} a p( Y ® p + p ® Y ) for some 
real coefficients ap. Writing this matrix out in the computational basis, the requirement that each 
2x2 block along the diagonal be positive semi-definite forces ax = &y = and all o>i = az- Then 
considering the first 3x3 block forces aj = 0. This gives the e = case, and a similar argument 
holds when \pp — ap\ < e for e > 0. The stability exponent d — 1/4 may not be optimal. □ 

Starting with the fact that |0) is determined by {Z} with exponent 1/2, we will apply several 
closure properties to bootstrap into a large class of tomographically determined states. 

Lemma 6.4 (General closure properties). If a G C(H) is a state determined by S — {Pi, . . . , P s } 
with exponent d, then: 

1. For any unitary U G C(H), UaU^ is determined by {UPU^ : P G S}, with the same exponent d. 

2. For any invertible s x s matrix V , a is determined by {X^e[s] VijPj : ^ ^ HI > w ^ ^ e same 
exponent d. 

3. For \^') E H f a pure state determined by S' with exponent d' ' , a ® l^'X^'l is determined by 
{P / : P G S}U {I P' : P' G S'}, with exponent at least min{d, d'/2}. 

In particular, the set of XZ -determined pure states is closed under tensor products. 

Proof 1. Let p be a state such that for all P G 5, \Tr((U 'PU ] )(UaU ] - p))\ < e. Since the trace 
is cyclic, this implies that maxp \TvP(a -U^pU)\ < e. Since a is determined by 5, therefore 
\\p - UaU^Wtr = \\U^pU - a\\ tr < ce d . 

2. Let p be a state and define a vector x by X{ = Tr Pi(p— cr). If for all i G 5, | Tr ( J2j VijPj{P ~ a )) | = 
\(Vx)i\ < e, then max^l < where 1 = ma^ :m ^ yi \< 1 max i \(V~ 1 y) i \. There- 
fore, ||p — cr||tr < c ||^ _1 |li i ed - 

3. Let 7r = Let p be a state on H ® let p^ = Tr^/ p and p%/ = Tr^p. As- 
suming that for all P G 5 and P' G S", |Tr(P ® l)(a ® tt - p)| = |TrP(a-p^)| < e and 
|Tr(l <g> P')(o" ® - p)\ = \TtP\tt - p n t)\ < e, it follows that \\p n - a\\ tl <ce d and \\p n > - 7r|| tr < 
c'e^ . Therefore, Tr(7rp%/) > 1 — 5, where 5 = c f e d . By Corollary 3.5 of the Gentle Measurement 
Lemma, \\p — pu ® 7r||t r < 2\/5 + 5, so \\p — a ® cr 7 || tr < 2\/J + 5 + ce rf . □ 

Closure under tensor products has been shown previously by McKague [McKlO, Lemma 3.4]. 
Note that in this third statement, it is important that one of the two states in the tensor product be 
pure. If a and a' are two mixed states determined by S and S", respectively, then a ® a' is generally 
not determined by {P ® I : P G S} U {I ® P' : P' G S f }. For an example, consider a = a r given by 
the third example in Lemma 6.3, and take p = ±|0+)(0+| <g> |0+)(0+| + ||+0)(+0| ® |+0)(+0|. 

Corollary 6.5. If a is a state determined by S C {/,X,y,Z}^ n ; anrf Q G {/,X,y,Z}^ n i5 any 
Pa?/Zz operator, then QaQ^ is also determined by S, with the same exponent. 

Proof. By the first closure property of Lemma 6.4, QaQ^ is determined by {QPQ^ : P G 5}. For 
Pauli operators P and Q, QPQ^ is either P or — P, depending on whether P and Q commute or 
anti-commute, respectively. By the second closure property of Lemma 6.4, with V a diagonal matrix 
with ±1 entries along the diagonal, QaQ^ is determined by S. □ 
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Recall that a stabilizer state is an n-qubit pure state |^) for which there exists a set of 2 n distinct 
and pairwise commuting operators S C {±P : P G {/, X, Y, Z}® 72 }, the stabilizer group, such that 
P\ip) — |^) for all P E 5 [NCOO]. Any set of n operators that generate the stabilizer group S are 
called stabilizer generators for \ r ijj). 

Theorem 6.6. A stabilizer state is determined by any of its sets of stabilizer generators. 

Proof. For any stabilizer state E (C 2 )® 72 and set S of stabilizer generators, there exists a Clifford 
group unitary U such that U\ip) = \0 n ) and {UPtf : P E S} = {Z i? . . . , Z n }. Indeed, to find 
such a J7, first choose a Clifford operator V such that V\t/j) = \0 n ). V conjugates S to some 
set of independent operators in {/, Z}® n . Using CNOT gates, this set can then be conjugated 
to {Zi, . . . , Z n }. By the tensor-product closure property of Lemma 6.4, |0 n ) is determined by 
{Zi, . . . , Z n }. By the unitary conjugation closure property of Lemma 6.4, therefore |^) is determined 
by S. ' ' ' ' ' □ 

Theorem 6.7. If E (C 2 )® 71 is a stabilizer state that has a set of stabilizer generators in 
{I,X,Z}® n , and if U is the tensor product of any n single-qubit real unitaries, then U\ijj) is 
XZ -determined. 

Indeed, |^) is XZ-determined by Theorem 6.6, and the set of XZ-determined states is closed 
under conjugation by tensor products of one-qubit real unitaries: 

Lemma 6.8. If a E £((C 2 )® n ) ^ s an XZ -determined state and U is the tensor product of n 
single-qubit real unitaries, then UaU^ is XZ -determined. 

Proof. The key idea is that for any state p, the {/, X, Z}® n coefficients of pU are determined by, 
i.e. , are a function of, the {/, X, Z}® n coefficients of p. Therefore, if p has {/, X, Z}® n coefficients 
close to those of UaU\ then pU has {J, X, Z}® n coefficients close to those of a. Since a is 
XZ-determined, therefore pU « a in trace distance, and SO rZl UaUi. Now let us give the formal 
proof, using the closure properties of Lemma 6.4. 

Without loss of generality, it suffices to consider the case that U acts as the identity on all 
but the first qubit. Any one-qubit unitary with real coefficients can be expanded as a product of 
operators of the form e l0Y and Z. Since Pauli operators fix the set of XZ-determined states by 
Corollary 6.5, it suffices to consider the case U = e l0Y ® J^C™ -1 ) . 

By the first closure property of Lemma 6.4, UaU^ is determined by {UPU^ : P E {/, X, Z}® n }. 
For P E {I,X,Z}^ n - l \ 

U(I®P)U ] =I®P 

U(X ® P)U ] = (cos(2(9)X + sin(20)Z) ® P 
U(Z <g> P)U ] = (- sin(2fl)X + cos(2(9)Z) ® P . 

Thus U conjugates operators in {/, X, Z}® n to linear combinations of operators in {/, X, Z}® n . 
Since the matrix ^^(20) co^(2#j) ls mver ^ible, the second closure property of Lemma 6.4 implies 
that UaU^ is XZ-determined. □ 

It is still unknown whether or not every state with real coefficients in the computational basis 
is XZ-determined, a question first posed in [MMMO06]. The problem is that whereas single-qubit 
real unitaries conjugate X and Z to combinations of X and Z, multi-qubit real unitaries need not 
do so. We can, however, show one last relevant closure property: 
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Lemma 6.9. The set of states determined by {/, X}® n U {I, Z}® n is closed under applying CNOT 
gates. 

Proof. A CNOT gate conjugates operators in {/, X}® 12 to {/, X}® 72 , and conjugates operators in 
{/, Z}® n to {/, Z}® n . Therefore this is a special case of the first closure property in Lemma 6.4. □ 

This proof does not work for arbitrary XZ-determined states since CNOTi^AT ® Z)CNOT{ 2 = 
-Y®Y. 

For later reference, let us state explicitly several special cases of Theorem 6.7: 

Theorem 6.10. Letting |^*) = ^(|00) + |H))> the following are complete, orthonormal sets of 
XZ-determined states: 

• {|0>,|1», 

• {U ® P\i/j*} : P G {I, X, Y, Z}}, for any one-qubit real unitary U, and 

• {(Pi, 2 ® CNOT 3 ,4)(|V*>i, 3 ® 1^)2,4) :?e{/, y Z}® 2 }. 

Finite tensor products of these states are XZ-determined, as are the same states multiplied by 
arbitrary single-qubit real unitaries. 

In our applications, we will use the states {|0), |1)} for initialization and readout, and will use 
the other two sets of states for teleporting into the gates of a quantum circuit. The CNOT gate 
and single-qubit real unitaries form a universal gate set for quantum computation. 

6.2 State tomography protocol 

In this section, we present a protocol by which Eve can certify that Bob has nearly honestly prepared 
a set of XZ-determined states. We first assume that Alice honestly measures her halves of the 
shared EPR states in either the X or Z eigenbases when requested. We then combine the protocol 
with a set of sequential CHSH games to ensure that Alice plays honestly. 

Definition 6.11. A state tomography protocol is parameterized by natural numbers q, n and m, 
with qn < m, a q-qubit POVM Q with at most 2 q outcomes, and a list a of qn distinct indices 
from [m]. The protocol involves a verifier, Eve, and two provers, Alice and Bob. Alice and Bob 
share a state in %a ®7~Lb- The protocol proceeds as follows: 

• Eve's interaction with Alice has m rounds. In round j, Eve sends Alice an independent, 
uniformly random bit, Aj. Alice applies a two-outcome projective measurement on T~La to 
determine her reply Xj E {0, 1}. 

• Eve has one round of interaction with Bob. First, Eve sends Bob the list a. Bob returns to 
Eve a string Oi, . . . ,O n; with the Oj E [2 q ] determined by successive 2 q -outcome projective 
measurements onHs- 

No other communication is allowed. 

Alice's strategy is ideal, with respect to an isometry U A : %a c_ ^ (C 2 )® m ® %' A , if in round j of 
her interaction with Eve, Alice returns the result of measuring the jth qubit in either the {|0), |1)} 
basis, if Aj — Q, or the {|+), |— )} basis, if Aj — 1. 

Alice and Bob's joint strategy is ideal, with respect to the isometries U D : Hd c— ^ (C 2 )® m ®l~i! D , 
D E {A,B}, if Alice's strategy is ideal with respect to U A and if 
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1. The initial state consists of m EPR states in tensor product with a state in T~L' A ® T-L f B , and 

2. Bob returns the results of measuring with Q each successive block of q qubits specified in a. 

To specify Eve's acceptance criterion, we will need the following notation: 

Definition 6.12 (Notation for a state tomography protocol). For j E [n] and i E [q], let = 
a(j_i} q +i E [m]. For o E [2 q ] n , let p Q be the normalized state of the system conditioned on Bob 
outputting (Oi, . . . , O n ) = o but before any of Alice's measurements. Let (p )aj be the same state 
reduced to Alice's qubits a(j, 1), . . . , cr(j, q). 

Let Pj — 5A a ^ i) ^Z + SA a ^ ji) ,iX E {X,Z} be the Pauli basis Alice is asked to measure in 
game a(j, i). Further, for o E [2 q ] and P E {/, X, Z}, let 

lf P = to 3 A s P,i + S P>P i(-l) x ^) . (6.3) 

That is, I?*'*' 1 = 1, I?*'*'^ = {-l) x «(3A, and otherwise lf' P = 0. For P e {I,X,Z}i, let 

1°' — T\ie[q] 1 > ^ I -PI ^ e ^ e number of coordinates in which P is not the identity, and let t°' P 
be given by 

-- p = ^ e >r ■ «") 

The motivation for r° ,p is to give an estimator for Tr(EjP) when Alice and Bob use an ideal 
strategy for the POVM Q = {E Q }: 

Lemma 6.13. If Alice and Bob's joint strategy is ideal and the POVM Q = {E Q }, then 

• The Oj variables are independent of each other, and satisfy Pr[Oj — o] — ^ Tr E Q . 

• For all j, Alice's state (p 0l ...o n )a,j equals Ej./TrE 0j . 

• The I° ,P variables are independent for different j, and satisfy E[7j' P ] = t^\p\ Tr(EjP)/ Tr E Q . 

Proof. For Pauli operators P and say that P E Q if in every coordinate either Q is the identity 
or P and Q agree. Thus for Q E {J, X, \{P E {X, Z}®* : P E Q}\ = 2<H^. Let X PeQ equal 1 

o P o P 

if P E Q, and otherwise. Notice that I- 1 — Soj^X^pieP^j 1 • ^he s ^ a ^ e °f Alice's g qubits after 
Bob measures outcome o is E^/TtE . Then a calculation gives 

P] Tr(PjP)/ Tr P = Tr(PjP)/ Tr P . □ 

We study state tomography for a POVM Q = {7r°} consisting of projections onto XZ-determined 
pure states. In particular, this implies that each tv° equals its transpose. Our state tomography 
theorem shows that if Eve accepts with high probability, then for most of Bob's measurement 
outcomes Oi, . . . , O n and most j E [n], (pOi...O n )cj,j is close to tt°k We begin by analyzing a state 
tomography protocol in which Alice's strategy is ideal: 

Theorem 6.14. Fix Q = {71- 1 , . . . , 7r 29 } a complete, orthonormal set of q-qubit XZ -determined pure 
states. For n sufficiently large, let m = m(n) > qn and let a E [m] qn be a list of distinct indices. 
Consider a state tomography protocol with parameters q, n, m, Q and a, in which Alice plays 
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according to an ideal strategy. Say that Eve accepts at the end of the protocol if the following two 
checks are satisfied: 



max |#{j : Oj = o} - n/2 q \ < A q ^n logn (6.5a) 



max |r°' p - Tr(^°P)| < A q J(\ogn)/n . (6.5b) 

This protocol satisfies the following completeness and soundness conditions: 
Completeness: If the provers' joint strategy is ideal, then 

Pr[Eve accepts] > 1 - 0(n" 1/2 ) . (6.6) 

Soundness: IfPv[Eve accepts] > 1 — n _1 / 4 ; then 



Pr 



\{j e [n] : Tr(( POl ...oJ^) > 1 - 0{n-^)}\ > (l-O^ 1 ^))^ > !_ n -i/8. (6>7) 



Proof. Let k = 4 q . Let us first show the completeness criterion. Since each Oj is drawn independently 
and uniformly at random from [2 g ], Pr[max G \#{j : Oj = o} — n/2 q \ < ky/n log n] >l — 2 q - 2n~ 2k , 
by Hoeffding's inequality and a union bound. Since tv° is an XZ-determined state, it necessarily has 
only real entries and therefore equals its transpose. Thus again Hoeffding's inequality and a union 
bound imply that for any t > 0, 

Pr[max|T°' P - Tr(^°P)| >t]< 2 q 3 q • 2 exp(-t 2 n/2 4 ^ +1 ) . 

Substitute t = k^ogn)Jn to get Pr[Eve accepts] > 1 - 0{n~ k ' ! /2 4,?+1 ) = 1 - 0{n- 1 / 2 ). 

Next we will argue soundness. Let e = n -1 / 4 and assume that Pr[Eve accepts] > 1 — e. Then 
there is at least a 1 — ^J~e probability that Bob outputs a string o\^ n — (oi, . . . , o n ) such that 
Pr[Eve accepts | 0\^ n — oi^ n ] > 1 — yfe. Fix such a transcript. 

In Alice's actual interactions with Eve, she measures her qubits in order, 1, 2, 3, . . . , m. We will an- 
alyze instead a hypothetical protocol in which Alice measures her qubits in order cr(l,l),cr(l,2),..., 
a(n, q — 1), a(n, q), . . .. Since Alice's strategy is ideal, and in particular her measurements commute, 
the distributions of her measurement outcomes are the same in the hypothetical protocol as in 
the actual protocol, so Eve accepts with the same probability. For j E [n], define the random 
variable aj to be the reduced density matrix of Alice's qubits cr(j, 1), . . . , cr(j, q) immediately after 
completing the first (j — l)q rounds of the hypothetical protocol. Let Pj — (X^Pj E {X, Z}® q be 
Alice's measurement bases for rounds (j, 1), . . . , (j, q). For J E [n], o E [2 q ] and Q E {/, X, Z}® 9 , 
define r°j ® and p°j® by 

2<i+\Q\ Q Q 2 q ^ 

ie[J\ je[J] 

Observe that Tj' Q - p°j Q , for J E [n], is a martingale. (Achieving this property is the reason behind 
our definition for Oj. Had we instead defined aj to be the state of Alice's qubits cr(j, 1), . . . , <r(j, q) at 
the beginning of her interactions with Eve, then r°j® — p°j® would not define a martingale sequence.) 
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Successive terms of the sequence differ by at most f (1 + 2^1) in magnitude. By Azuma's inequality, 
therefore, for any t > 0, 

HM Q - > 1 1 0l , n = o hn ] < 2exp ( - . 
Let N° — Ylje[n] ^Oj,o be the number of times Bob announces outcome o, and let 

je[n] 

be the average of the states aj over games in which Bob's outcome is o. Note that r° is a density 
matrix, i.e., r° y and Trr° = 1. Note also that 

Tr(r°Q) - fl* = - |) £ <5 0j , Tr(a,Q) . 

i€[n] 

If Eve accepts, so |7V° - rc/2*| < AVnlogn, it follows that |Tr(r°Q) - /# g | < 2 q ky/(logn)/n. 
Combining the above calculations, we find that for any t > 1 and S = 2t2 q k^/ (log n)/n, 

Pr [Eve accepts and max |Tr(r°Q) - t° ,( ^\ > S | 0\^ n = oi >n ] 

< Pr[max - p£«| > 5/2 | 1>n = o 1?n ] 

+ Pr[Eve accepts and max |Tr(r°Q) - p% Q \ > 5/2 \ 0^ n = o l n ] 

o,Q 

= Pr[max \t% q - p°>«| > 5/2 \ 1>n = oi,„] 

< 6 q • 2n~^+^ * , 

implying that for e = ye + 6 q • 2n 2 2 <?+3 ? 

Pr[Eve accepts and max |Tr(r°Q) - t°' Q \ < 8 I Oi ?n = o\ J > 1 - e / . 

Substituting t = 2 and k = 4?, note that e' = + 0(n- 229_1 ) = 0(y/e) and 5 = 6(1/ Vn). 

Assume that Eve accepts and max 05 g |Tr(r°Q) — r^'^l < 5. Letting 5' = 6 + A:^/ (log n)/n = 
6(1/ y/n), then for all o and all Q G {J, X, Z}® 71 , |TrQ(r° - tt°)| < 5', by Eq. (6.5b). Since r° 
is a density matrix and 7r° is XZ-determined, we conclude that there is a constant c such that 
\\r° — 7r° ||tr < c\f& . In particular, there is a constant c' such that maxg G {j |Tr Q(r° — tt°)\ < 
dy/5*. Thus, 

Pr[max|Trg(r -7r°)| < d\f5' I Oi, n = o t J >l-e . 

Assume that max 05 g |TrQ(r° — tt°)\ < d\f& . Since each r° is an average of states Oj, we will 
argue next, using a version of Markov's inequality for points lying in the unit ball, that aj is close 
to 7r°i for most j. 

Claim 6.15. Let x 1 , . . . , x n E H d each satisfy \\x J '\\ < 1. Let x = ^ • x J . // > 1 — 5, then for 
any p > 0, at least (1 — p)n of the x J must satisfy ||x J — x\\ < ^25/p. 
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Proof. Let v = x/\\x\\. Then since \\v\\ = 1, all x J satisfy xj • v < 1, whereas x • v = \\x\\ > 1 — 5. By 
Markov's inequality, at least (1 — p)n of the x J must have x 3 ' • v > 1 — 5/p. For each such x J , simple 
geometry on the unit ball implies that \\x J ' — x\\ < y/25/p. □ 

For a state p E £((C 2 )^) and a Pauli operator Q E {/, X, Y, Z}®*, let = Tr(Qp). Let p = 
(PQ : Q £ {/,X,y,Z}^) be the vector of weighted Pauli coefficients. Then ||p1| 2 = ^Eg( Tr Qp) 2 = 
Tr(p 2 ) < 1. Since tt° is a pure state, ||7r°|| = 1, implying that ||r°|| > 1 — 2 q / 2 c , y r 5 / ; . Applying 
Claim 6.15 for p = n" 1 / 8 , at least (l-p)N° of the j with Oj = o must satisfy - r°\\ 2 < p^c'Vfr. 

By a triangle inequality, also - < 5", where 5" = ^p q / 2 c f VS i + 2 q c , VS i = O^" 1 / 16 ). Thus, 
for J drawn uniformly at random from [n] , 

Pr[||aj - 7f^|| < 5" | Oi, n = oi >n ] > (1 - e')(l - p) > 1 - (e' + p) . 

By a Markov inequality, at least (1 — y/e' +p)n = (1 — 0(n _1 / 16 ))n of the coordinates j E [n] 
satisfy Pr[||<7j — 7r°j || < 5" \ 0\^ n — oi j7l ] > 1 — y/e r +~p. To complete the theorem, we will show: 

Claim 6.16. Letting 1 - rj = Pr - 7r°i || < 5" | Oi, n = oi >n ] , Tr((p )<^7r ') > 1 - 8" - 2rj. 

Proof. Observe that aj is a fixed function of the random transcript of Alice's interactions 

with Eve for rounds cr(l, 1), cr(l, 2), . . . , a(j — l,q — l),cr(j — l,g). Furthermore, since Alice's 
measurements in these earlier rounds are on qubits in tensor product with qubits a(j, 1), . . . , cr(j, q), 
it holds that 

(Po)aj= ?*[Aij-i = a lij -i\a j (a 1J - 1 ) . (6.8) 

a>i,j-i 

Indeed, in general, given a bipartite state p E C{%i ® %) and a set of Kraus operators E\ acting 
on H 2 and satisfying Y.i E \ E i = x > [t holds that Tr 2 p = £V Tr 2 ((l®£*)p(l®£j)) . Eq. (6.8) follows 
by letting Hi be the space of Alice's qubits a(j, 1), . . . , cr(j, g) and H2 be everything else, letting p 
be the initial state p Ql so Tr2 p — (p )aj, and letting the E\ be Eve and Alice's measurement 
operators for the earlier rounds. 

By linearity, Eq. (6.8) implies that also (p ]aj — Sai^-i P r [^-i,j'-i — a i,j-i]&j( a i,j-i)- Thus, 

\\(fr)*j-K°i\\< Pr [^-i = a iJ-i]||^( a ^-i)-^°i <iX-ri)5" + ri-2 . 

a i,i-i 

In particular, Tr((p ) aJ 7r^) = (p^j ' > 1 - (5" + 2r?). □ 

Thus for at least a l-0(n -1 / 16 ) fraction of the coordinates j, Tr^po)^-^') > 1 -0(n -1 / 16 ). □ 

Theorem 6.14 assumes that Alice's strategy is ideal. Next we will relax this assumption and 
allow both provers to follow dishonest strategies. To do so, we combine the state tomography 
protocol with a set of sequential CHSH games, analyzed in Theorem 5.39. 

Theorem 6.17. Fix Q = {71- 1 , . . . , 7r 2<? } a complete, orthonormal set of q-qubit XZ -determined pure 
states. For a sufficiently large constant a and for sufficiently large n, let m = m(n) > qn and 
N > m^ 1 . Let a E [m] qn be a list of distinct indices. Consider a combination of the following two 
protocols between the verifier, Eve, and the provers, Alice and Bob: 
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1. CHSH games: In the first protocol, Eve referees Nm sequential CHSH games. She accepts if 

\{j E [Nm] : AjBj = Xj ®Yj}\ > cos 2 (tt/ '8) Nm - ^^Nm\og{Nm) . (6.9) 

2. State tomography: In the second protocol, Eve chooses K E [N] uniformly at random. She 
referees (K — l)m CHSH games. For the Kth set, she referees a state tomography protocol 
with parameters q, n, m, Q and a. She accepts if the criteria of Eq. (6.5) are satisfied. 

The combined protocol satisfies the following completeness and soundness conditions: 

Completeness: If Alice and Bob use Nm shared EPR states to play the CHSH games according 
to an ideal strategy, and if Bob uses an ideal strategy with respect to the projections Q on 
the Kth set of m EPR states in the state tomography protocol, then in both protocols, 

Pr[Eve accepts] > 1 - 0(n" 1/2 ) . (6.10) 



Soundness: Assume that for both protocols, Pr[Eve accepts] > 1 — n -1 / 3 . Let p be Alice's state 
in the second protocol after (K — l)m games and conditioned on Bob's messages Oi, . . . , O n . 
Then there exists an isometry X A : %a c — ^ (C 2 )® 171 ® %' A such that letting p a j be X A pX A ^ 
reduced to Alice's qubits {a(j,i) : i E [q]}, 



Pr 



|{jE[n]:Tr(/^^ > 1 - An' 1 ' 12 . (6.11) 



Here, the probability is over K , the first (K — l)m games and 0\, . . . , O n . 

The isometries X A depend only on the first (K — l)m games, not on Oi, . . . , O n , and are the 
isometries promised by Theorem 5.39 for determining an m - a /( 32 ^) -ideal strategy for the Kth 
set of m CHSH games. 

Proof. The completeness condition for sequential CHSH games follows by Theorem 5.39 and 
Lemma 5.35. The completeness condition for state tomography follows by Theorem 6.14. 

Next we will argue soundness. Let e = n -1 / 3 and ( = m - a /( 32 ^) ? where is the constant from 
Theorem 5.7. Since the provers win the sequential CHSH games with probability at least 1 — e, by 
Theorem 5.39 there is at least a 1 — e — m~ a ^ probability that the provers' strategy for the KtYv 
set of m games is ("-ideal. 

Whether or not the provers' strategy for a set of games is ("-ideal is a property determined at the 
beginning of that set of games. It does not depend on any subsequent events. Since Bob's strategy 
for the first {K — l)m rounds is the same regardless of whether Eve is running CHSH games or 
state tomography, it therefore also holds that there is at least a 1 — e — m~ a / 8 probability that 
the initial state and Alice's strategy is ("-ideal for the Kth set of games in the state tomography 
protocol. By a union bound, there is at least a 1 — e — m~ a / 8 — 2n -1 / 12 > 1 — 3n -1 / 12 probability 
that, additionally, the probability that Eve accepts the state tomography protocol, conditioned 
on K and the (K — l)m previous games, is at least 1 — ^n -1 / 4 . 

Assume that the provers' strategy for the Kth set of CHSH games is ("-ideal and Pr[Eve accepts | 

previous (K — l)m games] > 1 — |n -1 / 4 . Using the notation from Theorem 5.39, this implies that 
there exist isometries X D : H D (C 2 )^ m ®H^ such that, letting X AB (p) = (X A ®X B )p(X A ®X B )\ 
\\X AB (pi) — pi || tr < C an d \[X AB £\ m (pi) — £i m {pi)\\ti ^ 2(". For notational simplicity, we can 
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embed U D into (C 2 )® m <g> extend the prover's measurements, and choose a basis so X — 1. 
Thus we have that 

||pi -Pi||tr < C 

ll^m(Pl)-A A m(Pl)Htr<2C . 

Let £ 5 be the measurement super-operator Bob uses to determine his responses Oi, . . . , O n . We 
have that S B (pi) = ^oe[2<7] n l°)(°l®Po f° r matrices p Q satisfying Trp = Pr[Oi . . . O n — o]. Similarly, 
£ B (f>i) = J2o \°)(°\ ® Po f° r certain matrices p Q . Let Oi, . . . , O n E [2 g ] be random variables dis- 
tributed according to Pr[Oi . . . O n = o] = Tr p . Then ^^(pi) — f ^(pi) || tr < ||pi — Pi||tr < C- By 
Lemma 3.2, the total variation distance between the distributions of O = 0\ . . . O n and O — 0\ . . . O n 
is at most £/2, and furthermore, letting p^ = p /Ti p Q and p^ = p /Trp , E[||pq — p^Htr] < 2£. 

For a state p, let p CT j be its partial trace onto Alice's qubits cr(j, 1), . . . , q). For 77 > and 

E [2 g ] n , define p to be rj-good for o if for at least a 1 — 0(n -1 / 16 ) fraction of the coordinates j E [n], 
Tr( P(7d TT 6 i) > 1-7?. 

Since Eve accepts £i m £ B (pi) with probability at least 1 — ^n -1 / 4 , and ||^ m f B (pi) — £^ m £ S (pi)||tr < 
2£, by Eq. (3.1) the same predicate accepts £\ m £ B (f>i) with probability at least 1 — ^n -1 / 4 — > 

1 — n -1 / 4 (for sufficiently large n). Since ^ m and pi are ideal, Theorem 6.14 applies. We obtain 
that there is at least a 1 — n -1 / 8 probability over O that po is 0(n _1 / 16 )-good for O. Since the 
distributions of O and O are £/2-close, there is at least a 1 — n -1 / 8 — £/2 probability over O that 
p' G is 0(n- 1 / 1 6)_ g ood for O. 

Since ||£ B (pi) — £ s (pi)||tr < C Lemma 3.2 implies that with probability at least 1 — over O, 
\\p'o ~ Po 1 1 tr < \/2C- By a union bound, there is at least a 1 — n -1 / 8 — £/2 — y/2£ > 1 — 2n -1 / 8 
probability that po is 77-good for O, where 77 = 0(n -1 / 16 ) + = 0(n -1 / 16 ). 

The inequality (1 - 3n _1 / 12 )(l - 2n -1 / 8 ) > 1 - 4n -1 / 12 completes our proof. □ 

In our application of Theorem 6.17, we will sample a uniformly random set S C [n] of fixed 
size s. With high probability, for all j E *S, Tr(p a j7r°i) > 1 — 0(n -1 / 16 ). Lemma 3.6 implies that 
the reduction of p to Alice's qubits {cr(j, i) : j E 5, i E [#]} is within 0(sn -1 / 32 ) from jG<s -7r°^ in 
trace distance. For this to be meaningful, we will pick s <C n 1 / 32 coordinates. 

A problem with Theorem 6.17 is that the soundness condition is hard to apply directly. The 
theorem gives us control over Alice's state conditioned on Bob's messages, but it does not say 
anything about the distribution of Bob's messages. The verification criterion of Eq. (6.5a) constrains 
Bob to report measuring 7r J on roughly a l/2 g fraction of his messages, for j E [2 q ]. However, he 
might, for example, output 0\ = • • • = O n /2Q = 1, = • • • = O271/29 — 2, and so on, following 

a deterministic strategy. Having to condition always on Bob's messages would severely complicate 
our later analysis. Therefore, we next extend Theorem 6.17 to show that on a random subset of 
the coordinates j E [n] , with high probability both p a j is close to tt°^ and Oj is distributed nearly 
uniformly. Thus the effect of Bob's super-operator on Alice's qubits for these coordinates is close to 
the effect of the ideal super-operator. 

It is possible to control the distribution of Bob's measurements because he shares with Alice a 
state that is close to a tensor product of EPR states, which to either party looks maximally mixed. 
The more he controls his measurement outcome the less effect the measurement has on Alice's 
portion of the state. The following lemma states this claim in a slightly more abstract setting: 
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Lemma 6.18. Let |^) = i J2ie[d] V^) ab®W) A>B> ^ C A ® C b ® ^ ® «b' and p = |^|, /or 
Hilbert spaces T-La' and %b' • Let £ B be the measurement super- operator for the computational-basis 
measurement on %b, ^.e v its Kraus operators are E{ — \%) ® (KX^Is ® IaA'B') for i E [d]. Let 
{II^} ; where i E [d] and £ varies over some finite set, be a complete set of orthogonal projections 
on c'g ® %b' • Let £ B be the super- operator with Kraus operators En = \i) ® (J^u)bb' ® ^-AA f / ^ 
corresponds to measuring i and £, and then tracing out i. Let pi = Y2i W^itWW 2 be the probability 
of measuring i, and when Pi > let Pi — ^ ^A'BB' X^-^p be the resulting state reduced to T-La- 
Assume that J2i:\\ Pl -\i){i\\\ tr < e Pi > 1 ~ e - Then > 

\\Tr B B>(£ B (p)-£ B (p))\\ tr < 31^/3 . (6.12) 

A state that is block diagonal defines a probability distribution over the blocks given by 
their traces, and defines conditional states given by the renormalized blocks. For two states that 
are simultaneously block diagonal, the trace distance between them is small if and only if their 
distributions over blocks are close in total variation distance, and if for most blocks, drawn according 
to either distribution, the conditional states are close. (See Lemma 3.2.) In this lemma, however, we 
are only given that the conditional states are usually close, and we need to show that this implies 
the distributions are also close. 

Proof of Lemma 6.18. Let 11^ = YZi^-H- The niain claim puts an upper bound on the probability 
of any outcome i for which pi is close to 



Claim 6.19. For any i with \\pi — |i)(i|||tr < 1; 

1 1 

- < - 
d~d 



Pi ~ -j < -j\\pi ~ \i){i\\\ tr • (6.13) 



Proof. Let c ijk = (fc, ^'lUlj, ?//). Then p { pi = \ £)j,fc c ijk\j)(k\ and Pi = \ J2j c ijj- Thus, using the 
general inequality ||cr||tr > Ej \ (jW\j)l 



S < 5/(2 -5)<5. Thus 



Ysj,k c ijk\j)(k\ > (\- Ciii \ _i_ ^j^j — 2 ^j/^ Ci ii 

Y2j C ijj tr ^ Y2j C ijj' Y2j C ijj Y2j C ijj 



Ij^iCijj. Since cm < 1, we have | 



Let 8 — \\\i)(i\ — pi\\tx < 1 and S — Y2j^i c ijj- Since cm < 1, we have | > S/(l + S), or 



11 S 



As a consequence of this claim, J2i \Pi ~ \ \ < 4e. Indeed, call an i E [d] "good" if \\pi — |i)(i|||tr < 
e, and "bad" otherwise. By assumption, Ebadz^ — e - Thus, by Claim 6.19, 

p? AA , BB ,(S B {p) - £ B (p))\\ tr = £>- a I 

i 

= 2 E fa- 1 *) 

i:pi>l/d 

< 2 E^ + 2 E (w-a) 

bad i good i 

< 4e . (6.14) 
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Therefore, we can immediately bound 
\\Tr A , BB ,(£ B (p)-E B {p)) 



tr 



= ® PiPi l*X*l ® I 

i i 

= ^2\\pipt- WML 

i 

<J2Pi\\pi-\i)(i\\L + ^\Pi-2 

i i 

' " \P: 



tr 



(6.15) 



Itr 



where we have applied a triangle inequality and used ||^|z)(z| — 

It takes more work to bound the trace distance without tracing out %a'- For i with pi > 0, 
let Ti = ^7 Trg#/ L^p. Then = Tr^/ T{. Let = Tr^r^. Intuitively, we are given by assumption 
that for most z, pi « which means that must be close to a tensor product ® p^. The 
additional conclusion of Eq. (6.12), compared to Eq. (6.15), is that p\ is usually close to Tr#/ \ r ij; , ){^ , \\ 



whereas Ty a >bb> £ B (p) = \ Y.% Wj\ 



MM 



, Tr BB , £ B (p) = \ Ei ® |iX*| ® Tr B , That 



is, not only does Bob's super-operator properly collapse Alice's half of the maximally entangled 
state 4^ X^i€[d] Im)ab> but a ^ so Bob's operation cannot significantly affect Alice's portion of the 
extra state \^ r ). Essentially, this is because Eq. (6.14) implies that for most z, pi is close to being 
uniform l/d — in fact, dpi ^ 1 up to a small additive error. However, a 1/d probability for outcome i 
already comes from the overlap of with the maximally mixed state ^1. For Bob's measurement 
to change substantially the state on the A 1 register, outcome i would have to have a substantially 
lower probability. 

Let p r — | 1 and p' A , — Tr#/ p 1 . Then we have 



\Tr BB ,(£ B (p)-£ B (p))\\ t] 



= ^ |*X*I ®Pin 

i 

= J2\\Pi T i~ 3"" 

i 



tr 



Pa> 



Itr 



By Corollary 3.5 of the Gentle Measurement Lemma, ||r, 
By definition, when > 0, 



® Pi lltr + WPiPi ~ \PA> lltr 

i 

^\\tr<Sy/T^{ 



(6.16) 



i\pi\i). 



^7 E li)(fc|A®Tr^[(n, 



Substituting = Tr A / gives (i|pi|i) = Tr [(Ui) BB 
Measurement Lemma, 



i)BB'\j){k\ B ® PA'B'] • 

B w p'a'b'] ' an< ^ so by the Gentle 



WW 



B 



] PA'B' ~ {^BB'WAb ® p'A'B'{^i)BB f \\ tr < 2\A 
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Use p\ = Tr A n = ^- Tr bb' [(^bb'^b ® Pa'b] and expand 1 = - (1 - to get 



\PiPi 



\PA>\\ tr 



< 



Tr bb' Qli) bb'Ib ® P a' B' - Tr BB'\i)(i\ B ® Pa'B 
(Ki)BB'\i){i\ B ® Pa'B'^bb' - V)(Ab® p'a>b> 



tr 



tr 



+ ^||(IIiW(l " Wt\)B ® pWCHiWHtr 

2 , 

< ^V 1 ~ dpi(i\pi\i) +pi(l - (i\pi\i)) • 

In the last step, we have used that the trace norm of a positive semi-definite operator equals its 
trace. 

Letting C{ — (i\pi\i) and substituting into Eq. (6.16), we find 



| Tr BB f (£ B (p) ~ £ B (p)) || tr < (3VT^Q + 2^1-dpid + (1 - a)) +2^2\ Pi 



i_ 

do 



We can next use the general inequality 1 — (i\pi\i) < ^\\pi — K)(i|||tr 5 but to make real progress 
we need to use the assumption X)i-||p i -|iVi||| tr >e^ — e - From Eq. (6.14), this assumption implies that 
£i \Pi ~ al < 4e - Let ^ = (4e) 2 / 3 . Call an i G [d] "great" if ||^ - |i)(i|||tr < e and dp* G y^] . 

By a Markov inequality and a union bound, J^great iPi — 1 ~~ e ~~ (4e) 1 / 3 . Thus, 



Tr^(^(p) - S B (p)) || tr < (3vV2 + 2^1 

< Sle 1 ^ . 



6/2 



l + r7 



+ (e + (4e) 1/3 )-6 + 2-4e 



□ 



For state tomography, the register A in Lemma 6.18 consists of Alice's qubits in the blocks 
indexed by the set S C [n] introduced above the lemma. For the application of state tomography to 
blind, verified computation, it is enough to trace away all of the quantum registers aside from A. 
Alice can compute using the states prepared by Bob in this register. Therefore, the bound in 
Eq. (6.15) is sufficient. However, for the application to simulating quantum multi-prover interactive 
protocols by classical protocols with entangled provers, we need Alice to work on additional input 
qubits, in the register A 1 that hold the quantum messages of the original QMIP system. 

For applying Lemma 6.18, it is convenient to make two minor technical modifications: first, 
to allow the initial state to differ from the ideal state, and second, to allow Bob to make more 
measurements. 



Corollary 6.20. Let p, £ B , {U i£ } and £ B be as in Lemma 6.18. Let p 



B 



be a state with 

\\p — p||tr < C- Let £ B be the super- operator with Kraus operators Em — \i) T <g> \£) L <g> (Hii)BB f ® ^AA'- 
Let pit = Tr(II^p) and pa = J- Tr a'bb' O^-iiP) • Then Tr LB B> £ B {p) = Tr B B> £ B {p) and, assuming 

^iMpu-\i)(i\\\u<ePM > 1 ~ e > 



\Tylbb' £ B (p) ~ Tr BB . £ B (p)\\ tl < 42 (e + C) 



1/6 



Proof. Let pi = J2ePtf and Pi = W Y.ePi£Pi£, so T^LA'BB' £ B (p) = Tr A , BB , £ B {p) = J2i 



(6.17) 

®PiPi. 
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Let us make the changes one at a time. The first extension, to the case of p « p is a simple 
corollary of Lemma 3.2. Let e > and assume for the moment that X}r||pi-|*X*llltr<£^ — ^ ~~ £m 
Since \\p - p\\ tv < C, Y,i \Pi ~ Pi\ < ( and Y,iPi\\Pi ~ PilW < Therefore, for any 5 > 0, 



E p*^ E 

\\pi-\i){i\\\tr<£+S \\ Pi -\i){i\\\tr<£+S 

\\Pi—Pi\\tr<S 



Pi 



> 



E 



\\pi_-\i){i\\\tr<£ 
\\Pi—Pi\\tT<S 



> pi ~ Y Pi~Y\ pi ~ pi \ 

i: i: i 

\\pi-\i){i\\\tr<£ \\Pi-Pi\\tr>S 



Fixing 6 = 2\/C, it follows from Lemma 6.18 and a triangle inequality that 

\ tr =\\Tr BB ,(S B (p)-S B ( P ) niu . 



\Tv BB ,{Tv L £ B (p) -€ B (p))\\ tr = \\Tv BB ,{£ B (p) -S B (p))\ 

<31(e + 2 v ^) 1 /3 + C . 



(6.18) 



It remains to use the assumption that J2i £-\\p i£ -\i){i\\\ tr <ePi£ — ^ ~~ e ^° determine an e such that 
X^r|| / o i -|iVi||| tr <e:Pi > 1 — £. Call an index z E [d] "good" if at least a 1 — y/e/2 fraction of the I, 
under the distribution p^ — pu/pi, satisfy \\pn — |i)(i|||tr < e - By assumption, X^good iPi — ^ ~ \/2e- 
Using the expansion pi = J2iPt\iPi£ an d a triangle inequality, for any good z, \\pi — |z)(z||| tr < 
(1 - v^72) e + • 2 < e + V2e. Thus e = e + \/2e works. Substituting this choice into Eq. (6.18) 

and simplifying gives Eq. (6.17). □ 

Theorem 6.21. With the same setup as Theorem 6.17, introduce the following notation, all 
conditioned on K and the outcomes of the first (K — l)m games. 

Let p\ be the provers' shared state at the beginning of the Kth set. Let X D : T~Ld c — ^ (C 2 )® m ®H! D , 
for D E {A,B}, be the isometries promised by Theorem 5.39 for determining a (-ideal strategy 
for the Kth set of m CHSH games, where ( = m - a /( 32 ^) . Assume that Bob's Hilbert space 
factors as Hb = Hbx ®^b 2 j an ^ that the isometry X B factors as X B — X Bl ® X B<2 , with 
X Bb '7-L Bb ^ (C 2 )® mb ® H' Bb , m 1 + m 2 = m and W B = W Bl ® U' B2 . Assume that a E [mi] qn and 
that Bob's measurement super- operator for the state tomography protocol is supported only on% Bl . 
If the provers' strategy for the Kth set of CHSH games is not (-ideal, then set X A , X Bl and X B<2 
arbitrarily. 

For a set S C [n], let £ B : C(Hb) C(C^- 2q ^ Sl ®%b) be Bob's measurement super- operator for 
the state tomography protocol in the Kth set, that stores in the first register Bob's messages Oj 
for j E S and traces out his other messages. Partition (C 2 )® m ®U' A as {U s ®Us) ® (C 2 )^ 2 ®W A , 
where %$ consists of the qubits listed in a, and %s consists of the remaining qubits, [mi] \ a. 

Then the following soundness condition also holds: 

Soundness 7 : Assume that for both protocols, Pr[Eve accepts] > 1 — n -1 / 3 . Let S C [n] be a 
uniformly random subset of size s < n 1 / 64 . Then there is a probability at least 1 — 0(n -1 / 48 ) 



66 



over S, K and the outcomes of the first (K — l)m games that for some state p[ E ^^a®^b^)^ 
the states 

Trs Bl X A X B2 S^( Pl )X A ^X B ^ (6.19) 

and 

^ E \oM®{®^° j ) s ®mm)Tk®p'i ( 6 - 2 °) 

oe[2<i}s jeS 

are within trace distance 0(n -1 / 384 ) of each other. Here, the partial trace that reduces to {T~Ls® 
( C 2)®m 2 ^/j (( C 2^m 2 a / 50 implicitly orders the qubits in S as a(j u 1), . . . , a(j u q) 

through a(j s , 1), . . .,a(j s ,q), where S = {ji, . . . J s }. 

Notice that the first terms in Eq. (6.20) are just the 5-fold tensor product of ^ ^oe[2<?] ® 7T °- 
This is exactly the state generated by an ideal state tomography strategy, reduced to the qubits 
for S. Note also that the EPR states |^*)^^ 2 shared between Alice and £>2 are approximately 
undisturbed. In our application of Theorem 6.21, the factorizations of %b and X B will be ensured 
by Proposition 5.40. 

Proof of Theorem 6.21. The proof boils down to rearranging equations so that we can apply Corol- 
lary 6.20 of Lemma 6.18. By Theorem 5.39 and the soundness condition of Theorem 6.17, with 
probability at least 1 — 2n -1 / 24 over K and the first (K — l)m games, it holds that: 

1. The provers' strategy for the Kth set of CHSH games is ("-ideal. In particular, choosing a 
basis so that the isometries X A = 1 and X B — 1, there exists a state E %' A ® %' B %c 
such that, letting |^) = \^*)® m <g> \^ f ) and pi = |^)(^|, \\pi - pi|| tr < C- 

2. There is at least a probability 1 — 2n -1 / 24 over the conditional distribution for Bob's messages 
Oi,n = (Oi,...,O n ) that 

\{j E [n] : Tr(p aJ * ') > 1 - S}\ > (1 - 6)n , 

where 8 = O^- 1 / 16 ). 

Fix K and transcripts for the first (K — l)m games satisfying these properties. 

Then in particular, with probability at least 1 - 2n~ 1 / 2A - O(sS) = 1 - 0(n~ 1 / 24 ), Tr^-vr ^ ) > 
1 — 6 for all j E S. Let p(Oi^ n ) be the state conditioned on Bob's messages Oi ?n and let ps(Oi, n ) = 
Tr^c p(Oi 5Tl ). By Lemma 3.6, there is at least a 1 — 0(n -1 / 48 ) probability over the choice of S 
that with at least a 1 — 0(n -1 / 48 ) probability over Bob's messages 0\^ ni 

\\ps(O hn ) - (g)^|| tr < 0(sVS) = 0(n- l ' M ) . 
jes 

Now apply Corollary 6.20. To translate into the notation of the corollary, let i represent 
Bob's messages Oj for j E £, t the other messages, d = 2 qs and e = 0(n -1 / 64 ). The registers A 
and A' correspond to U s and ((C 2 )®™ 2 ® H^) ® ((C 2 )®™ 2 <g> H^J, respectively, while 5 
and B' correspond to %Bi^ Hilbert space components %s and %s ® W B , on which Bob's super- 
operator is allowed to act. Thus pm — ps(Oi, n ) and = ®j e s /K ° j ^ satisfying the assumption 

£-\\p-i-\i)(i\\\tr<ePM — ^- ~~ e - Observe that up to local unitaries the state |^) is of the correct form; 
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if tt° = \ti°){ti \ for a unit vector \tt°) E C^l and \tt°) is the entry-wise complex conjugate of \tt°) 1 
then 

i$ = -i= E K^)®(i^r (m - 9re) ®i^)) 

V oe[2«] n j € [ n ] 

(Since the states tv° are XZ-determined, we may choose a phase so that in fact \tt°) = \tt°).) 

The states in Eqs. (6.19) and (6.20) are the same as the two terms in the trace norm in the 
conclusion of Corollary 6.20, Eq. (6.17), with p[ = Ty B ' C |?//)(?//|, except with Alice's space T~Ls 
additionally traced out. In the statement of the theorem, we have chosen to trace out the S 
register since the ideal reduced state on it is maximally mixed and therefore not useful for our 
applications. □ 



6.3 Process tomography protocol 

The state tomography protocol of Section 6.2 is a major step in allowing the classical verifier Eve to 
certify that the quantum provers Alice and Bob indeed apply a quantum circuit of Eve's choosing. 
However, it is not sufficient. State tomography allows Eve to certify that, before Alice begins her 
measurements, Bob has been nearly honest in remotely preparing a set of XZ-determined states on 
Alice's halves of the shared EPR states. By running the protocol with the provers' roles switched, 
and letting Alice go first, Eve could similarly certify that Alice has remotely prepared states on 
Bob's halves of the EPR states. However, state tomography does not let Eve certify that, when 
Bob goes first and collapses the EPR states, Alice's measurement operators on the prepared states 
have the correct effect. 

To link together the provers' actions, we need a stronger guarantee on their measurements. In 
this section, we will present and analyze a protocol for process tomography on Alice's measurements. 
State tomography lets Eve certify that Alice's measurements have nearly the correct effect on Bob's 
qubits, when Alice goes first. In contrast, process tomography will let Eve certify that Alice has 
applied nearly the correct measurement super-operators to her halves of the shared EPR states, 
regardless of which prover goes first. Similar to our analysis of state tomography, our analysis in 
this section will initially assume that Bob's strategy is ideal. 

It is not clear that state tomography, as we have presented it, implies process tomography. The 
basic problem is similar to an issue that arose in our analysis of sequential CHSH games in Section 5. 
Alice's strategy in early state tomography rounds might be sufficiently dishonest as to allow her 
in later rounds to apply completely dishonest operators. For example, if Alice manages in early 
rounds to swap her halves of EPR states qn — 1 and qn, and if she conjugates her later measurement 
operators by this swap, then her measurement operators will be far from ideal and yet will have 
nearly the correct effect on Bob's qubits when Alice goes first. This situation can certainly arise 
because our state tomography protocol only certifies a prover's actions in most rounds. A prover 
can cheat wildly in a few rounds and be confident that her actions will be indistinguishable from 
statistical noise. 

Potentially, we could weaken the definition of process tomography to sidestep this problem. After 
all, Eve does not care if Alice moves around her halves of the EPR states, so long as Alice and Bob 
together apply the correct circuit. Instead, though, the process tomography protocol we introduce 
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will allow Eve to certify that Alice has applied nearly the correct measurement in every round. A 
key idea to make this work is to restrict consideration to Pauli stabilizer measurements [Got97]. For 
Pauli operators in the stabilizer of a state, the measurement outcome is deterministic. Therefore 
Eve does not need to average any statistics. If Alice reports the wrong stabilizer syndrome in 
even a single round, then Eve will reject. Our analysis of the protocol will be similar to some 
of the arguments in Section 5. We will argue that Alice's earlier measurements cannot usually 
overly disturb the qubits intended for use in later measurements by pulling Alice's measurement 
super-operators over onto Bob's halves of the EPR states. 

For our applications, it suffices to apply process tomography to certify that Alice correctly 
applies two-qubit Bell-basis measurements, i.e., measurements of the stabilizer X ® X and Z ® Z. 
However, we have generalized our analysis beyond this case, to cover arbitrary r-qubit measurements 
of tensor products of X and Z operators: 

Definition 6.22. An r-qubit XZ stabilizer set is a subset of {I,X,Z}® r that consists of pairwise 
commuting Pauli operators that are multiplicatively independent. 

For example, TZ = {X <g> X, Z <g> Z} fits the definition for r = 2, as does TZ = {X <g> Z}. The 
independence condition implies that \TZ\ < r. 

Definition 6.23. A process tomography protocol is parameterized by natural numbers r, n and m, 
with rn < m, an r-qubit XZ stabilizer set TZ and a list a of rn distinct elements of [m]. The protocol 
involves a verifier, Eve, and two provers, Alice and Bob. Alice and Bob share a state in Ha ®Hb- 
The protocol proceeds as follows: 

• Eve has one round of interaction with Alice. First, Eve sends Alice a. Alice returns to Eve 
a string Oi, . . . , O n , with the Oj E {0, 1}^ determined by successive -outcome projective 
measurements on Ha- 

• Eve's interaction with Bob has m rounds. In round j, Eve sends Bob an independent, uniformly 
random bit, Bj. Bob applies a two-outcome projective measurement on Hb to determine his 
reply Yj E {0, 1}. 

No other communication is allowed. 

The initial state and Bob 's strategy are ideal if, up to local isometries, the initial state consists 
of m EPR states, possibly in tensor product with an additional shared state, and if in round j of his 
interaction with Eve, Bob returns the result of measuring his half of the jth EPR state in either the 
X eigenbasis, i.e., the {|+), |— )} basis, if Bj = 0, or the Z eigenbasis {|0), |1)} if Bj = 1. 

Alice and Bob's joint strategy is ideal if the initial state and Bob's strategy are ideal and, 
additionally, Alice acts by returning the results of measuring each successive block of r qubits listed 
in a according to the operators in TZ. 

If the provers' initial shared state is ideal, then by applying local isometries we may take 
U D = (c 2 )^™ ® U' D1 for D E {A,B}. The initial state is then |^) = |^*)^ m ® |^), for some 
l^ 7 ) £ T~L'a ® ® He, where He is an external space for purifying |^). Let p\ — I^X^I- 

For j E [n] and i E [r], let cr(j,i) = a^_i\ r+i E [m]. The bit (Oj)p of Alice's response to 
Eve denotes the outcome of allegedly measuring the operator P E TZ on qubits a(j, 1), . . . , cr(j, r). 
Without loss of generality, we will assume that Alice's responses are determined by a complete set 
of 2 n l 7 ^l orthogonal projections. In particular, the bit (Oj)p is determined by measuring a reflection 
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operator, and these operators commute for different j E [n] and P E 1Z. Formally, Alice's actual 
and ideal measurement super-operators are defined by: 

Definition 6.24. For j E [n] and P E 1Z, let R A p be the reflection that Alice measures to determine 
bit P of her response Oj. For o E {0, 1}, let P£ P (o) = \{1 + {-l)°Rf P ). For o E {0, l} n , let 
Pj^(o) = Ylp e ^jzPfp(op). Define a super- operator Q A by 

S}(P)= E \o :j )(o :j \0Pf(o :j )pPf(o :j ) . (6.21) 
Oj e{0,i}K 

This measurement super- operator implements Alice's strategy for determining the response Oj. 
For j E [n] and P E TZ, let R A p be the Pauli operator P applied to Alice's qubits a(j, 1) through 

r). Define the projections P A p (o) and P A (o), and Alice's ideal measurement super- operator Q A 

as above, but using the reflections R A p instead of Rfp- 

Let Ql n = G£... g£g£ and Q* n = ■ ■ ■ QfQf. ' 

On the other hand, for query b E {0, 1}, in the ideal strategy Bob measures the Pauli reflection 
RB = 5 bo x + S bA Z E {X,Z}. For b E {0, l} r , let R* = <g> i€[r ]££. For Pauli operators P 
and Q, say that Q E P if in every coordinate either P is the identity or P and Q agree (as 
in the proof of Lemma 6.13). Then Bob's measurements of the operators Rf, determine a ±1 

syndrome for any Pauli operator P such that R^. E P. For example, if a state \x/j) satisfies 
X ® J ® = -I ®Z® = I®I®X\ijj) = |^), then X® Z® I\i/>) = -|^). 

Theorem 6.25. Consider a process tomography protocol with parameters r, n, m, 1Z and a. Assume 
that the initial state f)\ and Bob's strategy are ideal. Say that Eve accepts at the end of the protocol 
if for all j E [n] and all P E 1Z with syndrome determined by Bob's measurements of his qubits 
a(j, 1), . . . , a(j, r), the syndrome is (— l)(°?) p . 

This protocol satisfies the following completeness and soundness conditions: 

Completeness: If the provers' joint strategy is ideal, then Eve accepts with probability one. 
Soundness: If Eve accepts with probability at least 1 — e, then 

PlniPi) ~ GUh)\\ tr < l0r2 r / 2 nVe . (6.22) 

Proof. As the completeness claim is immediate, we need only to argue soundness. The proof will 
work by pulling Alice's measurement super-operators across to ideal measurement super-operators 
on Bob's qubits, and then back. This proof strategy should be familiar from Section 5. However, 
the argument here is considerably simpler because we know by assumption that the initial state and 
Bob's strategy are ideal. 

Let us begin by defining Alice's ideal super-operators acting on Bob's qubits, similar to Defini- 
tion 5.21: 

Definition 6.26. For a fixed list a, for j E [n] and P E 1Z, let R^ p be the Pauli operator P 
applied to Bob's qubits a(j, 1) through a(j, r). Define the projections P^ p (o) and P^(o), and the 
super- operator fi A as in Definition 6.24 f or &f> but using the reflections R^ p instead of Rfp- Let 
f A — f A • • • f A 
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Observe that since a measurement on one half of an EPR state can be made equivalently on the 
other half, Q^ n {pl) = ^n(pl)- 

Since Eve accepts with probability at least 1— e, for every j E [n], there is at least a 1— e probability 
that for all P E H either the syndrome of P cannot be determined from Bob's measurements or the 
syndrome is ( — \)^°^ p . The probability that the syndrome of P can be determined is 1/2^1 > l/2 r , 
where \P\ is the number of non-identity components of P. Therefore, for all j E [n] and P E 1Z, 
there is at most a 2 r e probability that the syndrome of P disagrees with (Oj)p, given that it can be 
determined. Since Alice and Bob's different measurements all commute, this holds regardless of the 
order of the measurements. In particular, it holds when measuring the initial state p\. Expressing 
this condition algebraically, we have 

J2 Tt([i^p(o)®^p(o)]pi) > 1-Te , 

OG{0,1} 

which simplifies to 

Tr((Rf P ® Rf P )pi) > 1 - 2 • 2 r e . 

Next, we apply the following claim, a corollary of the Gentle Measurement Lemma: 

Claim 6.27. Let R E C(%a) and R r E C(Hb) be two reflections, and p E C(%a ®7~Lb) cl quantum 
state. Let 6 =1(1- Tr(R ® R')p) > 0. Then 

|| i(l + R) A p \ (1 + R) A - \ (1 + R') B p i(l + i2%|| tr < 2^5 + 35 . (6.23) 

Proof. Let II = ^(1 + i? ® i?'), a projection, and let II = 1 — II. By assumption, Trllp = 1 — 5, so 
also ||IIpII||tr = Trllp = 5. By the Gentle Measurement Lemma, Lemma 3.4, 

||p — npii||tr = ||npIT + npn + npTT|| tr < 2V5 . 

Together with two triangle inequalities, this yields 

\\p-u P \\ tr = \\u P \\ tT < ||npn||t r + ||npn||t r = i||npn + npn|| tr + ||TTpTT|| tr 
< i||p - npn||tr + flinpniitr 



In particular, \\p — (R (g) i2')p ||t r = \\RaP ~ RbPIUt < 2\/5 + 35. The claim follows by several more 
triangle inequalities. □ 

By Claim 6.27 with 5 = 2 r e, Alice's super-operator determining her response bit (Oj)p can be 
pulled over to Bob's side: 

I E \o)(o\®pM°)pi p M°)-I1 + 

oG{0,l} OG{0,1} 

Therefore, 

\\Gf(pi) -^/(Pi)|| tr < 2^1(2^ + 35) < 10r2 r / 2 v^ . 
Since the different super-operators Qj and all commute, this implies that, as claimed, 

\\QtAh) - OUML = Kn(Pi) - Kn(h)\\ tr < n ■ lO^/ 2 ^ . n 
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As for the analysis of state tomography, from Theorem 6.14 to Theorem 6.17, the next step is to 
combine the process tomography protocol with sequential CHSH games, in order to handle the case 
that Bob plays dishonestly. 

Theorem 6.28. Let 1Z be a fixed r-qubit XZ stabilizer set. For a sufficiently large constant a and 
for sufficiently large n, let rn = m(ri) > rn and N > m a ~ 1 . Let \ib be a distribution over lists of rn 
distinct elements of [m] . Consider a combination of the following two protocols between the verifier, 
Eve, and the provers, Alice and Bob: 

1. CHSH games: Eve referees Nm sequential CHSH games. She accepts if 

\{j E [Nm] : AjBj = Xj®Yj}\ > cos 2 (7r/8)7Vm - ^=y/Nmlog(Nm) . (6.24) 

2. Process tomography: Eve chooses K E [N] uniformly at random. She referees (K — l)m CHSH 
games. For the Kth set, she draws a from \ib and referees a process tomography protocol 
with parameters r, n, m, 1Z and a. She accepts if for all j E [n] Alice's reported syndromes 
for P ElZ agree with the syndromes that can be determined by Bob's measurements. 

Let G = exp(-ify) = (™ S j ) and let U act on £((C 2 )® m ) by U(p) = G® m pG^ m . The 

combined protocol satisfies the following completeness and soundness conditions: 

Completeness: Assume that Alice and Bob share Nm shared EPR states, that they use in sequence 
to play the CHSH games according to the ideal strategy of Table 1. Assume that Alice applies 
Q®m -j- fo er haiyes j the se f f m EPR states and then uses the qubits to play according 
to the ideal process tomography strategy. Then in both protocols, 

Vr[Eve accepts] > 1 - 0(n" a/4 ) . (6.25) 

Soundness: Assume that for both protocols, Vi[Eve accepts] > 1 — n~ a ^ . Let pi be the state in 
the second protocol after (K — l)m CHSH games, at the beginning of the process tomography 
sub-protocol. Let A : C(U A ) -+ £((CH)^H ® (C 2 )^( rn ) ® Ha) be the super- operator im- 
plementing Eve's interactions with Alice in the process tomography sub-protocol; it begins by 
appending the state [ib((t)\(t)((t | e £((CW)«(™)) and then appl ies Alice's process tomog- 
raphy measurement super- operator Q^ n controlled on a. Let the ideal super- operator for Eve's 
interactions with Alice be A, acting on £((C 2 )® m ®T-L f A ); like A, it appends X^cr M^( cr )l (J )( cr l 
and then applies W^Qx^a- Both pi and A depend on the first (K — l)m CHSH games. 

Then with probability at least 1 — 0(n~ a / 16 ) over K and the first (K — l)m CHSH games, the 
provers' strategy for the Kth set is m~ a ^ 32 ^ -ideal with respect to the isometries given by 
Theorem 5.39, X D : U D ^ (C 2 )® m ® H' D , for D E {A, B}; and furthermore, 

\\X A A(pi)X A i - A(X A Pl X A ^\\ tr = 0(n 1 - a /( 64K *)) . (6.26) 

To prove this theorem, we first study the case of combining a process tomography protocol with 
a set of sequential CHSH games for which the provers' strategy is ("-ideal by assumption. By having 
the provers play multiple sets of CHSH games and interrupting Alice before a random set, we can 
substitute into Theorem 5.39 to justify this assumption. 
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Theorem 6.29. Consider a protocol in which the verifier Eve can choose to run one of two sub- 
protocols: either m sequential CHSH games, or a process tomography protocol with parameters r, n, 
m, 1Z and a. In the latter case, Eve accepts if for all j E [n] Alice's reported syndromes for P E 1Z 
agree with the syndromes that can be determined by Bob's measurements on the indicated qubits. 

Assume that the provers' strategy for the sequential CHSH games is (-ideal with respect to 
isometrics X A and X B , and assume that Eve accepts in the process tomography sub-protocol with 
probability at least 1 — e. Let G — exp(— i^Y) and let U be the super- operator that applies G 
transver sally. Then 

\\X A g A (Pi)X A * -U2 l g A U A {X A Pl X A ^)\\ tr < Wr2 r / 2 n^7+( + 2( , (6.27) 

where p\ is the provers' initial state, and Q A and Q A are Alice's actual and ideal measurement 
super- operators for the process tomography protocol, depending on a. 

Proof By Definition 5.37, letting X AB (p) = (X A ® X B )p(X A ® X B )\ there exists a state pi = 
(|^*>(^*|)® m ® p[ such that \\X AB (pi) - pi||tr < C and \\X AB G B (pi) - £^ m (pi)\\tr < where Q B 
is the complete super-operator implementing Eve's interactions with Bob and £ B m is Bob's ideal 
super-operator for m CHSH games. Note that Bob's view in the process tomography protocol is 
the same as in the sequential CHSH games, so he follows the same strategy in both cases. From 
Table 1, Bob's ideal strategy for each CHSH game is based on measuring his half of an EPR 
state |^*) with one of the reflections R B =0 = ( \ } x ) or R B =1 = ± ( _\ z\ ). Since Rfi = G^XG 

and Rf = G^ZG, Bob's ideal CHSH game strategy is equivalent to his ideal process tomography 
strategy up to a change of basis by G. That is, Bob's ideal measurement super-operator for process 
tomography is given by Q B = UsSf^U^ 1 . Since (G <8> G)\ip*) = |^*) and thus UaUb(pi) = Pi, this 
implies that \\U A U B X AB g B { Pl ) - t B {pi)\W < K- 

Embed T~Ld into {C 2 )® m ®l~L r Dl extend the prover's measurements, and choose a basis so X D = 1. 
Let pi = UaUbPi. Then U A U B X AB G B (pi) = U B G B U B ' (pi) , giving 

\\Pl - Pl||tr < C 

\\u B g B u B \p 1 )-G B {h)h.<K • 

Since Eve's acceptance predicate involves only the transcript registers and not the provers' 
internal state, it accepts G A G B {pi) and U A U B G A G B {pi) = {UaG A U^){^ b G b U~ x ){J){) with the 
same probability, at least 1 — e. Therefore, by Eq. (3.1) the predicate accepts (UaG A ti U a 1 )G E '(pi) 
with probability at least 1 — e — \ • 2£. 

Since G B and p\ are ideal, Theorem 6.25 applies. We obtain 

\\{U A Q A Uf)(h) - Q\pi)\ Xx < 10r2 r / 2 ny^7TC . 

Since U A U B ( Pl ) = Pi, \\{U A Q A U^){h) - Q A {pi)\\ tv = \\Q A {pi) ~ (W/S A WA)(pi)|| tr , which implies 
by a triangle inequality that 

\\Q A {pi) - iU^g A U A ){ Pl )\\ tr < 10r2 ) '/ 2 nV^TC + 2C - 
Up to reinserting the isometries X A , this is our objective. □ 



73 



Proof of Theorem 6.28. We first argue completeness. By Theorem 5.39, if Alice and Bob play the 
sequential CHSH games using an ideal strategy, then Eve accepts with probability at least 1 — m~ a ^. 
Recall that Bob's ideal CHSH game strategy is equivalent to his ideal process tomography strategy 
up to a change of basis by G. If Alice makes the same basis change, then the effect is cancelled 
out, since (G ® G)\rp*) = |^*). By Theorem 6.25, Eve therefore accepts the process tomography 
protocol with probability one. 

Next we will argue soundness. Let e = n~ a ^ 8 and £ = t^-^A 32 ^*^ where is the constant from 
Theorem 5.7. Since the provers win the sequential CHSH games with probability at least 1 — e, by 
Theorem 5.39 there is at least a 1 — e — m~ a / 8 probability that the provers' strategy for the Kth set 
of m games is ("-ideal. By a union bound, there is at least a 1 — e — ra -a / 8 — \fe > 1 — 0(n~ a / 16 ) 
probability that, additionally, the probability that Eve accepts the process tomography protocol, 
conditioned on K and the {K — l)m previous games, is at least 1 — y/e. By a Markov inequality, 
at least a 1 — e 1 / 4 fraction of the a are "good", in the sense that Eve's conditional acceptance 
probability is at least 1 — e 1 / 4 . By Theorem 6.29, 

\\X A A{ Pl )X A ^ - A{X A Pl X A ^)\\ tr < [I0r2 r / 2 n(e 1 / 4 + Q 1 / 2 + 2C] + 2e l ' i , 

where the final 2c 1 / 4 term accounts for the trace distance for bad a terms. The right-hand side of 
this inequality is Ofa 1-0 ^ 64 "*)). □ 

7 Verified quantum computation 

Consider a classical verifier, Eve, who wishes simulate measuring the first qubit of C|0 m ), where C 
is a quantum circuit that uses T gates from a fixed, constant-size set of two-qubit gates. Known 
algorithms for this problem scale exponentially with T, and assuming that BQP ^ P, i.e., that 
classical computers cannot efficiently simulate polynomial time quantum computers, there is no 
polynomial-time algorithm. 

In a verified, blind quantum computation protocol, we allow Eve to interact with two quantum 
provers, Alice and Bob, who share a polynomial in T number of EPR states 4|(|00) + |11)). The 
interaction begins with Eve announcing T to the two provers. Then after polynomially many 
further rounds of interaction, provided that Alice and Bob cooperate, Eve will have her simulation 
result — except that with a probability exponentially small in T Eve will incorrectly accuse Alice 
and Bob of cheating. 

Furthermore, if Alice and Bob are dishonest and share an arbitrary entangled state but cannot 
communicate with each other, then the protocol will satisfy the following soundness conditions: 

• Authentication/ Verification: Either Eve detects cheating with probability at least 1/2, or 
the final measurement distribution obtained by Eve differs from the correct measurement 
distribution in total variation distance by at most e. 

• Blindness: Alice and Bob learn nothing about the quantum circuit C aside from its size T. 
(For example, they do not even learn the number of qubits it involves.) More precisely, once 
given T, each prover could alone perfectly simulate the distribution of transcripts of the 
prover's interaction with Eve. 

Here e > is a parameter chosen by Eve. It can be inverse-polynomially small in T. Note that the 
probability of catching Alice and Bob cheating can be improved by serial repetition of the protocol. 
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Also, if Eve wishes to hide, imperfectly, the circuit size T from Alice and Bob, she can pad the 
circuit with extra gates. 

In this section, we will present and analyze a protocol for verified, blind quantum computation. 
In fact, the protocol we give will also work for outsourcing the computations of a quantum 
verifier in a quantum multi-prover interactive proof (QMIP) system. Formally, we show that 
QMIP [A; provers] C MIP*[/c + 2 provers], where verified quantum computation can be seen as the 
k — case. Necessary background on quantum multi-prover interactive proofs is given in Section 7.1 
below. 

Our protocol combines four sub-protocols. First, a sequential CHSH game protocol establishes 
the provers' qubits. Second, a state tomography protocol establishes a set of XZ-determined resource 
states on Alice's qubits. Third, a process tomography protocol ensures that Alice honestly makes 
Bell basis measurements. Up to the choices of parameters, these protocols have been described 
earlier, in Section 6. The fourth protocol does the computation, based on teleporting through the 
resource states. 

Section 7.2 reviews computation by teleportation, after which we present the protocol. It will 
be straightforward to show that Eve's simulation works when the two provers are honest, except 
with exponentially small probability. The blindness property will also be straightforward. However, 
establishing the authentication condition is more of a challenge, and will rely heavily on our results 
for state and process tomography. A new problem, though, is that in computation by teleportation, 
the questions Eve asks the provers depend adapt ively on their previous answers. Even process 
tomography with soundness exponentially close to one can be unsound when used in a general 
adaptive protocol. We solve this by arguing that, roughly, no information is conveyed from Alice 
to Bob or vice versa when Eve chooses her questions adaptively to implement computation by 
teleportation. 

7.1 Multi-prover interactive proof systems with quantum entanglement 

A quantum multi-prover interactive proof system for a language L is a protocol of one or more rounds 
between a verifier and a number of provers. All parties are given an input string x, and the goal of 
the provers is to convince the verifier that x belongs to L. The verifier runs in quantum polynomial 
time and can send and receive quantum messages. The provers are quantum computationally 
unbounded, and may share an arbitrary entangled initial quantum state, but cannot interact with 
each other once the protocol begins. The number of provers, the number of rounds, and the sizes of 
the messages are all restricted to be polynomial in \x\. A language L is in the class QMIP if there is 
a quantum multi-prover interactive proof such that if x E L, the provers can convince the verifier to 
accept with probability at least 2/3; and if x ^ L, then no strategy of the provers can convince the 
verifier to accept with probability greater than 1/3. 

The class MIP* consists of those languages decidable by a QMIP system in which the verifier 
runs in probabilistic polynomial time and all messages are classical [CHTW04] — equivalently, MIP* 
is the same as MIP except with the provers allowed to share initial entanglement. 

QMIP systems can be parameterized more finely according to the number of provers, the 
completeness and soundness parameters, and the number of turns or rounds of communication. 
(A turn is an interaction in which messages are sent in one direction, either from the provers to 
the verifier or vice versa. A round consists of two turns.) The class of languages decidable by a 
proof system with one prover is known as QIP, for which three turns suffice [KWOO, MW05], and 
which equals IP = PSPACE [JJUW11]. Thus with a single prover, allowing quantum messages and 
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computation does not increase the power of the proof system. QMIP is a much more mysterious 
class. Whereas languages in the analogous classical class MIP can be decided by proof systems with 
only two provers [BGKW88], no similar reduction is known in the quantum case; while of course 
QMIP [2 provers] C QMIP [A: provers] for k > 2, it is not known whether any of these inclusions are 
strict. Even for the case of two provers, there is no better upper bound known than the set of 
all languages [KKM+11]. 5 Of course, QMIP contains MIP*, but no lower bound better than IP 
has been known for either class. Very recently, though, it has been proposed that MIP* contains 
MIP = NEXP [IV12]. 

Nonetheless, Kempe et al. [KKMV09] have shown several simplifying transformations for QMIP 
systems. They show: 

1. Any QMIP system can be parallelized to a three-turn system with the same number of provers, 
with perfect completeness and soundness parameter at least an inverse polynomial away from 
one. Moreover, the verifier's message in the transformed protocol is the same to all provers: a 
single, uniformly random, classical bit. Also, in the first turn, only the first prover sends a 
message to the verifier. 

2. By adding one prover, the system can be further parallelized to one-round (two turns), still 
with perfect completeness and soundness parameter at least an inverse polynomial away from 
one. By parallel repetition using a polynomial number of additional provers, the soundness 
parameter can be made exponentially close to zero. 

In our conversion of a QMIP system to a protocol with a classical verifier Eve, we will assume 
that the system has the first simplified form. This is quite convenient for us, because the verifier in a 
general QMIP system might act in ways that subvert our converted protocol's security. For example, 
she might forward messages from one prover to another, allowing them limited communication. 
These messages might not help the provers in the original QMIP system. However, in our converted 
protocol the original verifier's quantum workspace is stored with the provers and hidden from them. 
The provers could use the extra messages to reveal this workspace to each other, breaking soundness. 
It might be possible to deal with this by freshly hiding the quantum workspace before revealing 
any messages to the provers, but that would be complicated. Another advantage of starting with a 
simple three-turn QMIP system is that it allows us to separate the tomography sub-protocols from 
the computation sub-protocol that actually simulates the original QMIP system. In our converted 
protocol, Eve decides at random whether to run tomography or computation sub-protocols and 
does not tell the provers. The provers cannot learn which sub-protocol they are in because Eve 
can simulate the verifier's public coin message for the original system. Were we to start with a 
general QMIP system, however, this would not work and the provers could quickly learn which 
sub-protocol they were in. We would need to run tomography simultaneous to computation. While 
these problems might be fixable with more work in the conversion procedure, it is much simpler for 
us to start with a three-turn, public-coin QMIP system. 

7.2 Computation by teleportation 

A quantum algorithm can be implemented in three stages, initialization, computation and readout. 
The initialization stage prepares a state |0 m ), the readout stage measures the qubits in the compu- 

5 If the verifier is given a trusted, polynomial-size quantum advice state, the resulting class QlP/qpoly contains all 
languages [Raz09]. 
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(a) (b) 



Figure 5: (a) Computation by teleportation. By applying a Bell basis measurement to |^) and 
one half of the resource state (J ® (UP))\^*), the unitary U is implemented on |i/>), up to a 
correction UQPU^. Q is a Pauli operator determined by the outcome of the Bell measurement, 
(b) A computational-basis measurement on |^) can be implemented by a Bell basis measurement on 
|0) or ® |1). 



tational basis, and the computation stage consists of applying a sequence of const ant-qubit unitary 
gates drawn from a universal gate set. The idea of measurement-based quantum computation is 
to eliminate all unitary operators and to implement computation using only adaptive local mea- 
surements. One such scheme is the "one-way quantum computer," which uses adaptive single-qubit 
measurements on a large, highly entangled cluster state [RB01]. Computation by teleportation, on 
the other hand, uses two-qubit measurements on resource states with up to four qubits [GC99]. 
Let Q be the gate set consisting of the two-qubit controlled-NOT gate, or CNOT, and a 7r/4 

rotation about the y axis of the Bloch sphere, G := exp(— i^Y) = ^ sin(^-/8) ^os^i/s)^)' ^ e g a ^e 
set Q is universal, meaning that any quantum circuit can be efficiently compiled to use Q [Shi03]. Let 
H = (} Ji), the Hadamard gate, and let |^*) = ^(|00) + |11)), an EPR state. Nielsen [Nie03] 
has shown: 

Theorem 7.1 (Computation by teleportation [Nie03]). There exists a polynomial-time classical 
control procedure A that on input the description of a quantum circuit C that uses m qubits and T 
gates from the gate set Q, outputs a sample from a distribution that is exp(— fi(T)) close in variation 
distance to the distribution of measuring the outputs of C|0 m ) in the computational basis. The 
procedure A uses O(TlogT) copies of each of the quantum states 

|0), (I®H)\r), (I®GW), CNOT 2)4 (|^) ® • (7.1) 

A applies Bell basis measurements, i.e., measurements in the basis {(/®P)|^*) : P E {I, X,Y, Z}}, 
to pairs of qubits decided on adaptively. Aside from Bell basis measurements on the resource quantum 
states, A is fully classical. 

The procedure A works according to a simple extension of standard quantum teleporta- 
tion [BBC + 93]. The basic step of teleporting into a gate U using a resource state (/ ® U)\ip*) is 
shown in Figure 5(a) (and see [Leu02]). Depending on the outcome of the Bell basis measurement, 
a correction UQU^ may be required, for a certain Pauli operator Q. When teleporting into a 
Hadamard or CNOT gate, this correction is always another Pauli operator, since H and CNOT 
are in the Clifford group. A does not actually correct for Pauli errors, but simply stores them 
as part of the "Pauli frame" [Kni05], and uses them to update later Bell measurement results. If 
U = G, then the correction is not necessarily a Pauli operator, but it is always a Clifford operator: 
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Figure 6: Once for each |0) preparation, CNOT or measurement in C, and twice for each G gate, 
Eve asks Bob to prepare resource states of all the five types. To do so, he can apply this circuit to 
his halves of eleven shared EPR states and report to Eve the measurement results. 



GXG^ = iHY, GYG^ = Y and GZG^ = H. (The operator G lies in the third level of the Clifford 
hierarchy [GC99].) Therefore after attempting to teleport into G, there is a 50% chance that A 
needs to teleport a Hadamard correction onto the output. 6 The computational-basis measurements 
in the final readout stage of the circuit can be implemented by a Bell measurement that uses an 
extra |0) ancilla, as shown in Figure 5(b). 

Theorem 7.1 is relevant for us because all of the resource states in Eq. (7.1) are XZ-determined, 
by Theorem 6.10, so the state tomography protocol of Theorem 6.17 can be applied to verify 
their preparation. Moreover, a Bell basis measurement is the same as measuring the two-qubit 
XZ stabilizer set {X ® X,Z ® Z}, an operation to which the process tomography protocol of 
Theorem 6.28 applies. In our two-prover verified quantum computation protocol, the classical 
verifier Eve will run A. She directs Bob to prepare the necessary resource states on Alice's qubits, 
and she asks Alice to apply Bell basis measurements to certain pairs of qubits. 

Our protocol will actually slightly modify the procedure A. Instead of the resource states of 
Eq. (7.1), use the set of resource states 

{P\0), (HP) 2 \r), (GY) 2 \r), CNOT 2) 4P 2 Q4(|V>*> ® m) ■ P,Q e {I,X,Y,Z}}. (7.2) 

Then to teleport into an G gate, for example, use the next available (GP^IV**) resource state, regard- 
less of the Pauli P. P can be accounted for by a change in the Pauli frame; see Figure 5(a). Nielsen 
suggests using these resource states for a constant-factor efficiency improvement — whereas projecting 
a uniformly mixed state onto (1 G)\ij)*) fails with probability 3/4, a complete measurement in the 
orthogonal basis {(GP)2\ip*) ' P E {I, X,Y, Z}} will always give one of those four states. For us, 
efficiency is not the concern, but we want to limit the ways Eve's messages to Alice depend on Bob's 
reported measurement outcomes, i.e., on which of the four states {(GP^IV**) : P E {/, X, Y, Z}} 
Bob claims to have prepared. Our protocol will also use plain |^*) resource states. After each G 
gate, Eve will direct Alice to teleport into either an (/ ® H)\ij)*) state or a |^*) state, depending on 

6 Alternatively, since H — G 2 ' Z ', Nielsen proposes repeatedly attempting to teleport into G until no correction is 
required — after a constant number of trials in expectation. 
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whether or not a Hadamard correction is needed. Finally, primarily for notational simplicity but 
also to aid in obtaining the blindness property, Eve will always ask Bob to prepare all five of the 
different types of resource states together, and not just the particular resource state that is needed 
for the next step of computation. Figure 6 shows the circuit that an honest Bob can use to prepare 
the needed resource states. 

7.3 Protocol for verified quantum computation 

Theorem 7.2. Let L be a language decided by a k-prover QMIP protocol with completeness c and 
soundness s, with c — s at least an inverse polynomial in the input size. Assume that the protocol 
has three turns, and that the verifier's message consists of a single, uniformly random, classical bit 
that is broadcast to all provers. Then L E MIP* ; decided by a protocol with k + 2 provers. 

Furthermore, if k = ; then the two-prover MIP* protocol is blind, meaning that the provers are 
not given the input string x and learn only the size of the verifier's BQP circuit. 

The case k — gives verified, blind quantum computation, at least for decision problems, 
since QMIP[0 provers] = BQP. We will explain the extension beyond decision problems below, 
after the proof. Of course, BQP C PSPACE = IP, so without the blindness property the inclusion 
in MIP* [2 provers] is immediate. The case k = 1 is subsumed by the known equality QIP = 
IP [JJUW11]. 

By the protocol transformation of [KKMV09] and since trivially MIP* [A: provers] C QMIP[/c provers], 
Theorem 7.2 implies: 

Corollary 7.3. QMIP[fc provers] C MIP*[fc + 2 provers]. In particular, QMIP = MIP*. 

Theorem 7.2 might appear to be straightforward given our state and process tomography 
theorems, and the computation by teleportation procedure. The special form of the QMIP protocol 
ensures that the provers will not be able to distinguish tomography and computation sub-protocols. 
The main problem, though, is that computation by teleportation is necessarily an adaptive procedure; 
after teleporting into an G gate, a Hadamard correction might be required. Prover strategies that 
pass tomography with high probability might be able to cheat in an adaptive protocol. 

A toy example should illustrate this problem. Consider a setting in which provers Alice and Bob 
share n + 2 n EPR states. Eve asks Bob to measure the first n EPR states in the computational 
basis and return the results; assume that he does so honestly. Eve asks Alice to measure one of 
the 2 n last EPR states. But Alice cheats: she compares the message from Eve with her halves 
of the first n EPR states and acts as directed only if they disagree. For any fixed message from 
Eve, this strategy will fail tomography tests with only an exponentially small probability. However, 
if Eve asks her questions adaptively, by forwarding Bob's measurement results to Alice, then her 
message will always agree with Alice's halves of the collapsed EPR states, so Alice will always cheat. 
Therefore, using tomographically verified procedures in an adaptive protocol requires some care. 

Proof of Theorem 7.2. Let V be the verifier and Pi, . . . , P& be the provers in the QMIP protocol. 
Without loss of generality, we may assume that the verifier's protocol has the following form: 

1. Receive m qubits from Pi and nothing from provers P2, • • • > Pfc- 

2. Choose b E {0, 1} uniformly at random, and send b to each prover. 
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3. Receive m qubits from each prover. Apply a circuit C to the (k + l)m message qubits and 
1 6) ® |0 m_1 ), where C consists of T C not CNOT gates and T G G = exp(-ifF) gates. Measure 
the first qubit of the output. Accept if the qubit is |1) and reject if it is |0). 

We may assume that only Pi sends a message in the first turn, because Pi's message can combine all 
of the provers' messages. We may assume that all messages have length m and that the verification 
circuit C uses m workspace qubits by padding messages and the workspace. 

Let us modify this protocol by adding an initial turn in which the verifier distributes EPR states 
that the provers can later use to teleport back their quantum messages. Precisely, the verifier's 
action in this new turn is: 

0. Prepare (k + l)m EPR states. Send the second halves of 2m of the EPR states to Pi, and the 
second halves of m EPR states to each of the other provers. 

The subsequent turns are the same, except the provers send 2m classical bits whenever they would 
originally have sent m qubits, and before applying C the verifier applies the appropriate teleportation 
Pauli corrections. It is without loss of generality to put the protocol into this form: 

Claim 7.4. The teleportation-based protocol has identical completeness and soundness parameters 
as the original protocol. 

Proof. Honest provers can use the EPR states to teleport their messages to the verifier, so the 
completeness parameter is unchanged. 

Dishonest provers might not follow the teleportation protocol, i.e., they might not apply Bell 
measurements to their halves of the EPR states. (For provers teleporting states, all messages in 
{0, l} 2m are equally likely, but dishonest provers might, for example, send the all-zeros string with 
probability one.) However, after applying the Pauli corrections, the verifier is in possession of some 
qubits that the provers might as well have teleported to her. More formally, a cheating strategy 
in which the provers do not teleport some quantum messages can be converted to a strategy in 
which they do teleport their messages. Indeed, consider placing between the verifier and prover Pj 
an intermediary Pj who intercepts the original EPR states sent to Pj and sends instead halves of 
freshly prepared EPR states. On receiving a classical message from Pj, Pj applies the appropriate 
correction to its halves of the new EPR states, and then honestly teleports them to the verifier. 
The verifier's reduced state, after applying the Pauli corrections, and acceptance probability are the 
same with or without these intermediaries. Since the combination of Pj and Pj now is honestly 
teleporting messages to the verifier, this can be converted to a cheating strategy for the original 
protocol. □ 

Now we are ready to present our converted (k + 2)-prover MIP* protocol. For clarity, we will 
define the protocol and the provers' ideal strategy simultaneously, but of course dishonest provers 
may deviate from this strategy. 

Call the verifier in the new protocol Eve. The two extra provers are Alice and Bob, while 
provers Pi through P& play the roles of the k provers in the original QMIP protocol. Let q = 11. 
Let a be a sufficiently large constant. Let n — 2((fc + 2)ra + TcNOT + ^b)- By padding the verification 
circuit if necessary, assume that n is at least a sufficiently large constant. Let n s — n a / 2 > n 64 
and N > In the ideal strategy, the provers start out with N sets of EPR states, each set 

consisting of n g — qn s + (k + l)m EPR states total: qn s EPR states shared between Alice and Bob, 
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2m EPR states shared between Alice and Pi, and m EPR states shared between Alice and each of 
the other provers P2, . . . , P&. 

Eve picks at random one of the following four sub-protocols to run, choosing the last sub- 
protocol with probability S = l/(6n Q: / 8 ) and choosing each of the first three sub-protocols with 
equal probabilities (1 — 5)/3. 

1. CHSH games: Eve referees N sets of sequential CHSH games, each set consisting of qn s games 

between Alice and Bob, 2m games between Alice and Pi, and rn games between Alice and 
each of the other provers. Eve accepts if the provers win at least 

cos 2 (7r/8)iVn 9 - ^Nn g \og(Nn g ) (7.3) 

of the Nn g games. By the Hoeffding inequality in Lemma 5.35, Eve will accept with probability 
at least 1 — (A^) -1 / 4 if the provers play the CHSH games honestly (where in each individual 
game Bob and Pi, . . . , P& all use the strategy for Bob in Table 1). 

2. State tomography: Eve chooses K E [N] uniformly at random. She referees the first K — 1 

sets of CHSH games, ignoring the results. She sends the questions for the Kih set of games 
to Alice. She chooses a uniformly random permutation a E S qUs1 and begins n s rounds of 
interaction with Bob. In each round, she reveals q entries of a to Bob, i.e., cr(l), . . . , a{q) in 
the first message, a(q + 1), . . . ,cr(2g) in the second message, and so on. She expects each 
time q bits in response. If Bob is honest, then he should start by applying G®^ 71 ^ to his EPR 
state qubits. Then in each round he should apply the circuit of Figure 6 to the qubits that 
Eve has specified, and return the measurement results. 

Eve treats this as a permuted-qubit state tomography protocol for the g-qubit states given by 
(S^)® g applied to the 2 q eigenstates of the measurement circuit of Figure 6. By Theorem 6.10, all 
of these states are XZ-determined (Definition 6.1). She accepts if the two criteria of Eq. (6.5) 
are satisfied. Note that unlike in Definition 6.11 for a permuted-qubit state tomography 
protocol, Eve gives the permutation a to Bob in pieces and not all at once. This only restricts 
the ways that Bob can cheat. By Theorem 6.14, if Alice and Bob play honestly, then Eve 

— 1/2 

accepts with probability at least 1 — 0(n s ). 

3. Process tomography: Eve chooses K E [N] uniformly at random. She referees the first K — 1 

sets of CHSH games, ignoring the results. For all of the provers except Alice, she also asks the 
questions for a Kth set of CHSH games. With Alice, however, she interrupts the protocol. 
She fixes r, a uniformly random list of (k + l)m + 2n distinct indices in [qn s ]. For (k + l)m 
rounds she sends Alice one index of the EPR states shared with the provers Pi, . . . , P&, and 
the next entry of r. Then for n rounds she sends Alice two entries of r at a time. In each 
round, she expects in response two bits from Alice. Ideally, Alice should start by applying 
Q®n g ^ ^ eY state qubits. Then in each round she should return the results of a Bell-pair 
measurement on her halves of the indicated qubits. That is, in the first (k + l)m rounds, she 
should apply Bell-pair measurements that cross between EPR states shared with Bob and 
with one of the Pj, and in the following n rounds, she should apply Bell-pair measurements 
between two EPR states shared with Bob. 

Eve treats this as a process tomography protocol (Definition 6.23) with r — 2 and 1Z — 
{X ®X,Z ' (g) Z}. She accepts if and only if in all rounds Alice's reported syndromes agree with 
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the syndromes that can be determined by the other provers' measurements. If the provers 
play honestly, then Eve accepts with probability one. Recall from Theorem 6.28 that the 
purpose of applying G transversally is to change basis so that the ideal CHSH game strategy 
for Bob and Pi, . . . , P& consists of X- and Z-basis measurements. Also, once more, revealing r 
incrementally instead of all at once only reduces Alice's opportunities for cheating. 

4. Computation: Eve chooses K E [N] uniformly at random and referees the first K — 1 sets of 
CHSH games. Then she asks Pi for the first message in the QMIP protocol. If Pi is honest, it 
applies G transversally to its EPR state qubits, and returns 2m classical bits, the Bell-pair 
measurement results needed for teleporting the first message. Eve chooses a bit b uniformly 
at random, and sends it to Pi, . . . , P&. If these provers are honest, then they will apply G 
transversally before returning 2m classical bits each, the measurement results needed for 
teleporting their messages in the turn three of the QMIP protocol. 

With b and these 2(k + l)m bits in hand, Eve wants to direct Alice and Bob to simulate the 
verification circuit C. 

Eve's interactions with Bob are identical to the interactions in the state tomography sub- 
protocol. Eve chooses a uniformly random permutation a E S qUs , and over n s rounds reveals q 
entries of it at a time, expecting q bits in response in each round. Whether or not Bob plays 
honestly, his strategy is identical to his strategy in the state tomography sub-protocol, since 
from his perspective there is no difference. 

Eve's interactions with Alice are similar, but not identical, to the interactions in the process 
tomography protocol. The permutation a gives the locations of where in Alice's qubits 
the g-qubit resource state blocks should be. The first block of resource states should be in 
positions <j(1), . . . , cr(g), and so on. Eve acts as though Bob is playing honestly and, one 
Bell-pair measurement at a time, she directs Alice to use these resource states to implement 
teleportation by computation, as explained in Section 7.2. In the first (k + l)m rounds, she 
directs Bell-pair measurements to teleport Alice's qubits from EPR states shared with provers 
Pi, . . . , Pk into resource states. She sets up the workspace of C, \b) ® |0 m_1 ), by using the |0) 
or |1) single-qubit resource states. Then she teleports between resource states to implement 
the gates of C, and finally she finishes with Bell-pair measurements onto the single-qubit 
resource states in order to implement the final measurement of C. 

Eve does not use all of the resource states. Although each g-qubit block contains five different 
types of resource states — see Figure 6 — Eve uses at most one of them. Furthermore, Eve uses 
at most n of the n s blocks. She chooses a uniformly random subset S C [n s ] of size 1^1 = n. 
Writing S — {ji, . . . , j n }, with j\ < J2 < " ' < jn, Eve uses only the blocks in S, in order. For 
the ith resource state, she uses the block of qubits cr((ji — l)q + 1), . . . , cr(jiq)- 

At the end, Eve accepts if the final measurement, adjusted by the propagated Pauli frame, 
gives |1), and she rejects if it gives |0). If the provers play honestly, then Eve accepts with 
the same probability as in the original QMIP protocol, which is at least the completeness 
parameter c. 

Although glossed over in the descriptions above, Eve must also time her messages to the provers 
to avoid leaking information about which sub-protocol she is running. This is fairly straightforward. 
Start by specifying the timing in the computation sub-protocol. The Kth set in this sub-protocol 
begins with two rounds — four turns — in which messages are exchanged between Eve and the provers 
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Pi, . . . , Pfc. Then there are n s rounds of interaction with Bob, and finally at most n rounds of 
interaction with Alice. To account for the first two rounds, add two rounds at the beginning of 
the first K — 1 sets, and of all the sets in the other sub-protocols, in which dummy messages are 
exchanged. Also, in process tomography, delay sending the first indices of r to Alice for n s dummy 
rounds, so that Alice cannot distinguish between process tomography and computation. Then, too, 
Bob cannot distinguish between state tomography and computation, Bob and Pi, . . . , P& cannot 
distinguish between process tomography and CHSH games, and Alice cannot distinguish between 
state tomography and CHSH games. Furthermore, observe that the timing of messages in each 
sub-protocol is fixed, so we can assume that the provers' strategies do not depend on the message 
timings. 

This protocol is an MIP* protocol; Eve is fully classical. Overall, if the provers play honestly 
and the input x lies in L, then Eve accepts with probability at least 

(1 - 5) - ^ {(Nng)- 1 '* + 0(n s -V2)) + §c > 1 _ (1 _ c)g _ 0(n -i/ 2) 

= l-(l-c + 0(n- a / 8 ))5 . 

Next assume that x ^ L. Assume that Eve accepts with probability at least 1 — e, where 
e = (l — \{c + s))5. Then for each of the first three sub-protocols, the probability that Eve 
accepts conditioned on choosing that sub-protocol is at least 1 — 3e/(l — 5) > 1 — 65 = 1 — n~ a ^. 
The probability that Eve accepts conditioned on choosing the computation protocol is at least 
l-e/5 = \{c + s). 

For analyzing the soundness of the protocol, we introduce a different version of the computation 
sub-protocol. Whereas in the computation sub-protocol, Eve's messages to Bob are chosen non- 
adaptively and her messages to Alice chosen adaptively, in the alternative sub-protocol, only Eve's 
messages to Bob are chosen adaptively. 

Note that in the computation sub-protocol, many of the messages Eve sends to Alice are fixed 
by a, independent of Alice and Bob's responses. For example, Eve wants the initial state to be 
1 6) (g) |0 m_1 ) only up to a Pauli correction, so she does not care whether Bob claims to have measured 
|0) or |1). In fact, all of the messages Eve sends to Alice are independent of Alice and Bob's 
responses, except for the two rounds immediately following teleportation into a G gate. For these 
two rounds, Eve's messages to Alice are adaptive, because she wants to apply either an / or an H 
correction to the output of the gate depending on the Pauli frame that entered it. This Pauli frame 
is determined by Alice responses in all of the previous rounds, Bob's responses in all of the rounds 
up and including the round that was meant to prepare the G resource state, and also the 2(k + l)m 
bits that Eve received from Pi, ... , P& — bits that determine the initial Pauli frame on Alice's qubits 
from EPR states shared with Pi, . . . , P&. With a fixed, there are therefore 2 T ° possible transcripts 
for the messages from Eve to Alice, two possibilities for each gate G. 

Alternatively, however, Eve can fix her messages to Alice in advance, and can change the 
permutation she gives Bob for the block of resource states following a G gate. She either leaves the / 
and H resource states (i.e., |^*) and (J ® H)\ip*), up to Pauli operators) alone, or she switches their 
positions. This defines the alternative computation sub-protocol; it is the same as the computation 
sub-protocol, except with the adaptive corrections made by switching the positions of the two 
resource states in Eve's messages to Bob. First, Eve picks a and S, then she interacts with Alice, 
then she interacts with Bob, introducing additional swaps into a adaptively when required. Note 
that the timing of messages is different in this alternative sub-protocol; Alice goes before Bob. 
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However, we have already argued that Alice and Bob's strategies do not depend on the timing, so 
in our analysis we can substitute the same super-operators into this alternative and hypothetical 
computation sub-protocol. 

Claim 7.5. Whatever Alice and Bob's strategies may be, running those strategies in the computation 
sub-protocol and in the alternative sub-protocol gives identical results. That is, the transcripts are 
identically distributed, and conditioned on any fixed transcript, the provers' joint states and Eve's 
private Pauli frames in the two sub-protocols are identical. 

Proof. The proof is by the principle of deferred decisions. Observe that since Alice and Bob act on 
different subsystems, their operators commute with each other, and the only important order is 
that imposed by Eve's adaptive decisions. In particular, we can imagine running Alice and Bob 
simultaneously. Let Eve fix the subset £, but defer fixing the indices of a until they are required. 
Consider a G gate in the circuit C. Run Alice up through the Bell measurement that teleports into 
that gate, and run Bob until stopping just before the preparation of the next block of resource 
states in S (i.e., if the gate uses block j% £ S, then stop before the preparation of block ji+i). The 
next step can be implemented in two ways: 

1. In the computation sub-protocol, Eve picks a list of q uniformly random qubit indices from 
unused qubits in [qn s ]. She sends these to Bob, and she sends to Alice the input position 
of either the I resource state or the H resource state, depending on whether a correction is 
required. 

2. In the alternative sub-protocol, Eve again picks a list of q uniformly random, unused qubit 
indices. She sends to Alice the second of these indices, i.e., the input position of the I resource 
state in Figure 6. She sends the q indices to Bob, but if a Hadamard correction is required, 
then she first swaps the indices for the / and H resource states. 

These two different rules generate exactly the same joint distribution of messages to Alice and Bob. 
The same is true for every G gate. Therefore, the computation sub-protocol and the alternative 
sub-protocol are actually the same, except for the order of the messages. □ 

Claim 7.5 is the reason why tomography characterizes the provers' strategies even though Eve's 
messages in the protocol are chosen adaptively — unlike in the toy counter-example at the beginning 
of this section. Using this claim and the tomography theorems, we can prove soundness of the 
protocol. 

So as to frame our analysis in terms of super-operators, let us define some notation for the 
portion of the computation sub-protocol after the K — 1 sets of CHSH games. Let Ha be Alice's 
Hilbert space, be Bob's Hilbert space and Hp be the tensor product of the Hilbert spaces of 
provers Pi, . . . , P&. Let T-£ be the space of transcripts for messages from Eve to Alice; it can hold n 
messages each holding two indices in [qn s \. Let T<^ = (C 2 ® C 2 )® n be the space of transcripts 
for messages from Alice to Eve. Let Ta — T-£ ® T<^ be the space of transcripts for all messages 
to and from Alice. Similarly, let T-g- = ^C^ qns ^ q )^ ns be the space of transcripts for messages to 
Bob — n s rounds of messages each consisting of q indices from [qn s ] — let = (C 2<? )® ns be the 
space for Bob's responses, and let Tp = T-g ® T^. Let T P = C 2 ® (c 2 )^( 2 ( /c+1 ) m ) be the space 
for transcripts between Eve and the provers Pi, . . . , P&. Let Tbp = Tb ® 7p, Tap = Ta®Tp and 
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Tabp — Ta^Tbp- As the transcripts in our protocol are classical, the states in these spaces will 
always be diagonal in the computational basis. 

Let p E C{%a ® H B ® Hp) be the initial state of the provers at the beginning of the Kth 
set. We will leave implicit the dependence of p, and of the super-operators defined below, on the 
transcripts of the first {K — l)n g games. Define a super-operator B : C(H B ) —> £(T B ®H b ) to 
implement the joint operations of Eve and Bob in the Kth set of the computation sub-protocol. 
This is the same as Eve's interaction with Bob in the state tomography protocol. B first appends 
a register ^ ^ J2 a eS qn I cr )( cr I £ >C(T-^), and then applies Bob's measurement super-operators 
for the n s rounds in the sub-protocol. Define a super-operator V : C(Hp) —± C(T P ® Hp) to 
implement Eve's interactions with the provers Pi, . . . , P&. Define a super-operator A a d : C(T B p ® 
Ha) — > C(Tpp ®Ta® Ha), as the super-operator describing Eve's adaptive interactions with Alice, 
controlled by the transcript of her interactions with Bob and Pi, . . . , P&. That is, applying A&& 
to a state Y,m BP \ m Bp)(m B p\ ® p(m BP ) gives J2m BP \ m Bp){m B p\ ® A^(m B p)(p(m BP )), where 
^ad( m Bp) • £(Ha) £(Ta ® Ha) is the super-operator conditioned on the transcript vn B p . In 
the original description above, Eve computes a random subset S C [n s ] and also keeps track of a 
Pauli frame for Alice's qubits. However, this private information can be computed, or uncomputed, 
from the transcripts, so the super-operator does not need to track it explicitly. Extend B to act as 
the identity on Ha ®Hp, and similarly extend V and A&d- Then conditioned on K and the first 
K — 1 sets of CHSH games, the computation sub-protocol finishes in the state 

A ad BV(p) e C(T AB p ®H a ®H b ® H p ) . 

Define similarly super-operators A : C(Ha) —> £(Ta <8> Ha) an d £> a d : £(Tap ® H B ) — > C(Tap ® 
T B ®T~L B ) as implementing, respectively, Eve's interactions with Alice and Eve's adaptive interactions 
with Bob in the alternative description of the computation sub-protocol. Note that A is the same 
as Eve's interactions with Alice in the process tomography sub-protocol. By Claim 7.5, no matter 
the provers' strategies, 

B^AP = Aed&P • (7-5) 

Since Eve accepts the CHSH games sub-protocol with probability at least 1 — 65, by Theorem 5.39 
there is at least a 1 — 65 — n g probability that the provers' strategy for the Kth set of CHSH 
games, conditioned on K and the first K — 1 sets, is ("-ideal, where ( = ng a ^ 32 ^ and ft* is 
the constant from Theorem 5.7. The strategy being ("-ideal means in particular that there exist 
isometries X A : U A ^ (C 2 )^ ® U' A and X B :H B ®H P ^r (C 2 )^ <g> H' BP , and some state p f 
such that, letting p = (|i*)(^*|)® n * ® ft, 

\\{X A ® X B )p{X A ® X B y - p||tr < C • 

The isometries X A and X B thus define ideal qubit locations in %a and in T~L B ® 1-1 p. (In fact, by 
following the proof of Theorem 5.7, it is not difficult to see that the isometry X B respects the 
decomposition % B ®Hp, i.e., factors as separate local isometries. We will not need this observation, 
however.) To simplify notation, we can embed Ha into (C 2 )® 77 ^ ®H! A and % B into (C 2 )® 77 ^ ®H' BP , 
and assume that X A and X B are both the identity. 

Define £?, v4 a d, A and B^ to be the ideal super-operators for provers who follow Eve's instructions 
in the Kth set of the computation sub-protocol up to a basis change by G. That is, they apply G 
trans versally, apply the specified measurements to the specified qubits of either (C 2 )® ng ® H! A or 
(C 2 )® 77 ^ ®H' BP , and then apply transversally. Let V be the verifier's acceptance predicate based 
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on the final transcript in Tabp\ it updates Alice's final reported measurement value according to the 
Pauli frame, and accepts if the result is |1). By Claim 7.4 and since {G®G)\i\)*) = |^*), the provers 
have a strategy in the original QMIP protocol that makes the verifier accept with probability exactly 

Pr[V accepts A ad BV(p)] . 

This probability is at most the soundness parameter s of the protocol, since x ^ L. Our 
goal is to relate X AB A dbd BV{p) to AadBV(p), and therefore to relate Pr[V accepts A dbd BV{p)} 
to Pr[V accepts A&&BV{p)}, in order to derive a contradiction. 

Start by using Theorem 6.28 for process tomography. Since Eve's acceptance probabilities in 
the CHSH games and process tomography sub-protocols are both at least 1 — 68 > 1 — n _Q: / 8 , the 
theorem applies. We obtain that with probability at least 1 — 0(n~ a / 16 ) over K and the first K — 1 
sets, 

\\X A A(p) - AX A (p)\\ tr = C^n 1 "^ 64 **)) . 

In particular, by Claim 7.5, 

A*dBP(p) = B ad VA(p) 

» B ad VA(p) (7.6) 
= A Bd PB(p) , 

where the approximation is up to error 0(n 1_Q: /( 64 ^*)) in trace distance. 

To finish, we would like to use the state tomography theorem, Theorem 6.21, to relate B(p) to 
B(p). Since Eve's acceptance probabilities in the CHSH games and state tomography sub-protocols 
are both at least 1 — n~ a / 8 > 1 — n^ 3 , the theorem applies. However, the theorem does not 
give so strong a claim. It only allows for approximating Bob's actual super-operator by his ideal 
super-operator if we also trace out Bob's Hilbert space, and Bob's responses and Alice's qubits for 
all but those corresponding to a random set S C [n g ]. Theorem 6.21 can be applied in our situation, 
but to do so we will need to introduce some more notation. 

Let S be the super-operator that acts as follows: 

1. First, based on the transcript of messages from Eve to the provers Alice and Bob, it extracts 
into a new classical register the subset S C [n s ] consisting of those blocks of EPR states that 
Eve has asked both provers to touch. 

2. Then it reorders those of Alice's qubits that are supposed to be entangled with Bob so that 
the qubits in the blocks of S come first. 

3. Finally, it traces out Bob's Hilbert space, the messages to and from Bob for rounds outside 
of 5, Alice's extra space % r A and all of Alice's qubits that are supposed to be entangled with 
Bob for blocks outside of S. 

Let S f be the super-operator that has the same second and third steps, but that chooses S uniformly 
at random in the first step. Continuing from Eq. (7.6), we have 

SA ad BV( P ) « SA^VBip) 

= A 3A ,sPS'B{p) , 
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where *4 a d,s is the ideal adaptive super-operator for Alice with the subset S fixed. Here, the equality 
SA&dB'P — A&dfiS'BV follows because the ideal super-operator A&d has no support on Alice's 
qubits that are supposed to be entangled with Bob for blocks outside of S. 

By Theorem 6.21 and a Markov inequality, with probability at least 1 — 0(n s 1 ^ 96 ) over K and 
the first K — 1 sets, 

\\S'B(p) - S'B(p)\\ tr < 0(n-V™) + 2 • 0(n~^) = 0{n~^) , 

where the term 2 • 0(n s 1 ^ 96 ) accounts for the trace distance for bad choices of 5. 

Putting together our calculations, we obtain that with probability at least 1 — (68 + n g a ^ 8 ) — 
0(n" a / 16 ) - 0(nJ 1/m ) = 1 - 0(n7 1/96 ) over K and the first K - 1 sets, 

SA aA BT(p) « SA^BV(p) (7.7) 

up to an error in trace distance at most 0(n 1 ~ a ^ 64zK ^) + 0(n 5 1 / 384 ) = 0(n~ a ^ 768K *^). In particular, 
since the verifier's acceptance predicate V does not depend on the messages to and from Bob for 
rounds outside of 5, in these cases we have 

Pr[V accepts A ad BV{p)] - \\\S'B{p) - S'B(p)\\ tv < Pr[V accepts A ad BT(p)} 

<s , 

the soundness parameter of the original protocol. 

Thus the probability that the verifier accepts the computation sub-protocol is at most (5 + 
0( n -a/(768/6*))) + 0(n~ 1/96 ) -1 = 5 + 0(n- a /( 768 ^*)). The 0(n~ 1/96 ) • 1 term is the contribution for 
those K and transcripts for the first K — 1 sets for which we cannot make the approximation of 
Eq. (7.7); in such cases, we can only upper bound Pr[V accepts A&(\BV(p)} by one. For a and n at 
least sufficiently large constants, s + 0(n~ a ^ 768K ^) < \{c-\- s). This is a contradiction. Therefore, 
on inputs x £ L, Eve must accept with probability less than 1 — (l — ^(c + s))5. Together with 
Eq. (7.4), this establishes an inverse polynomial completeness-soundness gap for our transformed 
MIP* protocol. Sequential repetition can be used to amplify the gap. 

For the claimed blindness property when k = 0, observe from Eq. (7.5) that each prover's view 
of the protocol consists of random messages, drawn from a distribution that depends only on the 
size of the circuit C. □ 

The above proof gives blind, verified quantum computation for decision problems. The same 
arguments extend beyond decision problems, though, e.g., to relation and sampling problems. In 
general, the verifier can referee many sequential protocols, each time picking a random one of the 
three testing sub-protocols, in order to gain sufficient statistical confidence that the provers are 
playing nearly honestly. At a random position, the verifier can insert the computation sub-protocol. 
The analysis is then the same as above. In particular, the arguments leading to the approximation 
of Eq. (7.7) still hold. 

It may be that in fact QMIPf/c provers] = MIP* [A: provers], without the need to add two additional 
provers. Our proof technique is useless for the k = 1 case, which is already known: QIP = IP. 
However, it seems likely that the technique should work for the case k > 2, with minor technical 
changes. The idea is to identify Alice with Pi and Bob with P2. We have not investigated it carefully, 
though. In the next section, we will present several other interesting open problems. 
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8 Open problems 



By characterizing the device strategies that can win many successive CHSH games, we have shown 
how a fully classical party can direct the actions of two untrusted quantum devices. The simplest 
case is device-independent quantum key distribution, free of the independence assumptions needed 
in previous analyses. Three main open problems are to extend the results to other non-local 
quantum games beyond the CHSH game, to improve the efficiency of our schemes and their 
analysis — of interest both for developing practical applications and for obtaining a better theoretical 
understanding of the underlying physics — and to find further cryptographic applications. 

1. The CHSH game is "rigid" in the sense that any strategy that achieves the optimum success 
probability can be related by local isometries to the ideal strategy of Table 1, and nearly 
optimal strategies can be nearly related to the ideal strategy (Lemma 4.2). What other 
non-local quantum games satisfy this property? Lemma A. 2 in Appendix A gives one example, 
but it is based on the CHSH game and its analysis inefficiently goes through Lemma 4.2. For 
games whose analysis cannot be reduced to studying pairs of two-outcome measurements, 
Jordan's Lemma (Lemma 4.3) will not apply, and new techniques will be needed for analytically 
controlling the provers' strategies. Can the rigidity of an XOR game be reduced to rigidity 
properties of the Tsirelson semi-definite program? 

If Lemma 4.2 extends to show the rigidity of a certain game, then it is likely that the sequential 
repetition theorem, Theorem 5.7, also generalizes. The main technical tricks for proving 
Theorem 5.7 involve shifting one prover's operations to the other prover's qubits (Section 5.3). 
This allows the derivation of a tensor-product structure within a prover's Hilbert space based 
on the tensor-product structure between the provers' Hilbert spaces. These tricks should apply 
to other non-local games based on maximally entangled shared states. 

2. Although our schemes have polynomial overheads and are therefore efficient in principle, the 
exponents are too large for any practical applications. The DIQKD key rate tends to zero, 
instead of a positive constant. Significant improvements are possible by tightening the analysis, 
which we have not at all optimized. However, new proof techniques are probably required 
to achieve a practical overhead. One approach might be to use ideas from fault-tolerant 
quantum computing [NCOO]. Fault tolerance can reduce the overhead if it allows for proving 
the same soundness guarantees from less statistical data. Just as important, fault-tolerance 
ideas might allow for tolerating higher noise rates, even constant noise rates. We would 
like our schemes to work even if the honest provers are somewhat faulty, as would be any 
real devices. In principle, this is not a problem for blind, verified computation, since the 
provers can work on top of a quantum error-correcting code and the verifier can help distill 
any faulty initial entanglement. Of course, a general-purpose quantum computer, capable of 
manipulating quantum error-correcting codes, is well beyond current technology. In contrast, 
quantum key distribution setups have been deployed and are commercially available [SBC + 09]. 
More sophisticated proofs might allow for device-independent QKD with today's experimental 
technology. 

Another aspect of efficiency is the number of rounds of communication. Can Theorem 5.7 be 
generalized to hold for games played in parallel instead of in sequence? A parallel-repetition 
theorem would allow for enforcing the assumption that the provers do not communicate 
based on space-like separation of the provers. One starting point might be to use the parallel 
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repetition analysis techniques of [KV11]. Reducing the round complexity of the blind, verified 
quantum computation protocol might be more difficult. Computation by teleportation, at 
least, inherently requires the coordination of adaptive corrections. 

3. The CHSH game rigidity theorems provide the foundation for device-independent quantum key 
distribution, for blind, verified quantum computation and for the equality QMIP = MIP*. The 
theorems do not have a classical analog and allow for drastically reduced security assumptions 
from what is possible classically, in particular the elimination of any computational assumptions. 
An important question is whether other cryptographic primitives or protocols, beyond what is 
possible classically, can also be based on CHSH game rigidity and state and process tomography. 
For example, Silman et al. have given a device-independent, imperfect bit-commitment protocol 
based on the Greenberger-Horne-Zeilinger (GHZ) game [SCA+11]. 
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A Characterization of nearly optimal strategies for an extended 
CHSH game 

The CHSH game in Lemma 4.2 establishes a shared EPR state between the provers Alice and Bob, 
as well as X and Z operators for Alice and operators (X ± Z)/y/2 for Bob. In this section, we 
extend the CHSH game with more questions in order that the rigidly determined ideal strategy 
should use Pauli Y operators, in addition to the X and Z operators, acting on the shared EPR state. 
Our extension follows along the same lines as McKague and Mosca's extension of the Mayers- Yao 
test [MM11]. However, it will not be possible to fully determine the Y operator, since the provers 
can coordinate to use — Y each instead of +Y with no detectable consequences, and can even do so 
coherently. A reflection of the Bloch sphere about the xz plane is a non-unitary symmetry, that 
cannot simply be absorbed into a change of basis. It corresponds to taking the complex conjugate 
of the coefficients of the state in the computational basis [Z eigenbasis). Similar to Lemma 4.2, we 
characterize, as far as possible, e-structured strategies for the extended CHSH game. 

Definition A.l. An extended CHSH game involves three parties: a classical randomized verifier or 
referee, Eve, and two quantum provers, Alice and Bob. Alice and Bob are not allowed to communicate 
with each other. They share two registers of an arbitrary pure quantum state E %a ®7~Lb ® Hc> 
where %a and %b are the Hilbert spaces of Alice and Bob, respectively, and %c is an inaccessible 
third Hilbert space. 

In the game, Eve twice and independently picks a uniformly random direction from the set 
{(1,0,0), (0,1,0), (0,0,1), ^(1,1,0), ^(1,-1,0), ^(1,0,1), ^(1,0,-1), ^(0,1,1), ^(0,1,-1)}, 

shown in Figure 7. She sends the first direction, a, to Alice, and the second direction, b, to Bob. 
Alice measures her portion of using a two-outcome projective measurement {nS, ni} ; and returns 
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Figure 7: An extended CHSH game with nine measurement directions, indicated here on the Bloch 
sphere, has embedded within it CHSH games in the xz, xy and yz planes. In the cross-section for 
each of these planes are the four measurement directions of Table 1. 



the result, x E {0, 1}, to Eve. Bob similarly returns to Eve y E {0, 1}, the result of the projective 
measurement {H^H^}. Therefore, for questions a,b, the probability of responses a,b is given by 

hy\m = (K X a®rtl®l C ) w . (A.l) 

In the ideal strategy, Alice and Bob return the result of measuring their halves of a shared EPR 
state 7^(100) + 1 11)); along the input direction, thought of as an axis for the Bloch sphere. That is, 

on input a, Alice measures with the projections ^(1 + a • (X, Y, Z)) and ^(1 — a • (X, Y, Z)), and 
returns x — on the first outcome as x — 1 on the second outcome. Bob follows the same ideal 
strategy. Thus the probability of outcomes x, y on questions a, b is 

*°y\* * • (*> * Z )) ® ^ J + * ■ Y > ^))^ m+m ■ (A - 2) 

For e > 0, call a strategy for the extended CHSH game e-structured if for all a, 6, x, y, 

\Pxy\ab Pxy\ab\ — ^ ' C^*^) 

To analyze the extended CHSH game, our approach is to apply Lemma 4.2 repeatedly. Observe 
that the extended CHSH game contains within it six CHSH games, i.e., sets of questions for 
which the extended CHSH ideal strategy is consistent with playing a CHSH game optimally. 
For example, the questions (a, 0) E {(1, 0, 0), (0, 0, 1)} x {^(1, 0, 1), ^(1, 0, —1)} form one such 

game, as do questions (a, b) E 0, 1), 0, -1)} x {(1, 0, 0), (0, 0, 1)}; there are two CHSH 

games along each plane xz, xy and yz. In an e-structured strategy for the extended CHSH 
game, each of these sub-games has correlation value at least 2\/2 — 16e, when questions a, b are 
appropriately relabeled by bits. (This follows by the definition of the correlation value in Eq. (4.1): 
4(2 Pr[x © y = ab] — 1) = 2 J2 a (3e{o 1} ^ T [ x ®y — ab\a — a^b — ^] — A.) Lemma 4.2 therefore applies 
to each sub-game, and we will then stitch together the conclusions. We show: 

Lemma A. 2 (Rigidity for the extended CHSH game). Consider a extended CHSH game, with 
the notation established in Definition A.l. Let e > and consider an e-structured strategy. Then 
there are extensions of the Hilbert spaces %a^b, and extensions of the reflections Z,X,Z f ,X' by 
a direct sum with other reflections, so that the following properties hold: 
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• Alice's space is isomorphic to C 2 ®1~La, with Z = Z <S> 1, \\(X — X ® 1)^|^)|| = 0{y/e), and 
for some reflection A E C(U A ), \\(Y-Y® A) A |V>}|| = 0(e 1 ' 12 ). 

• Bob's space is isomorphic to C> 2 ®'Hb, with ma J x{\\(Z / — Z ® l)^^}!!, \\(X f — X <g> 1)b\^)\\} = 
0(e 1 / 4 ) ; and for some reflection A' E C(H B ), \\ {Y' - Y ® A')b|^> || = C^e 1 / 144 ). 

• Finally, letting |^*) = ^(|00) + |H)), there exists a unit vector \ip x ) E ®^Hb ®T~Lc with 
|||^) - |^*) <g> |^ x )|| = 0(y/E) and (tp x |A ® A 7 |^ x ) > 1 - 0(e 1 ' 72 ). 

The constants hidden by the big-O notation are universal constants, independent of the game strategy. 

In the proof we will use: 

Lemma A. 3. Let U be a unitary and H a Hermitian operator, both acting on state \(j>), with 
\\H\\ < 1 and \\(U - H)\<f>)\\ < e. Then there is a reflection A such that \\(U - A)\<f>)\\ < e + 2 4 / 3 e 1 / 3 . 
Furthermore, if H = P ® H f , where P has eigenvalues ±1, then we may take A = P ® A 7 for a 
reflection A 7 . 

Proof. This is essentially a Markov inequality. Let 6 E (0, 1), a parameter that we will optimize 
shortly. For c E {0, 1}, let A c be the projection onto the span of the eigenvectors of H with 
eigenvalue within 8 of (— l) c . Let A = Aq — Ai, so |A| = Aq + Ai. Then, 

||(C/-A)|0)||<||(C/-i7)|^)|| + ||(i7-A)|^)|| 

<\\(U- H)\4>)\\ + \\H\A\ - A|| + (1 - 5)||(1 - |A|M|| . 

Here the first term on the right is at most e and the second term is at most S. To bound the 
final term, use 1 - e < ||f7|Y>)|| - \\(U - H)\</>)\\ < \\H\(/>)\\, and \\H\<j))\\ 2 < |||A||c/>)|| 2 + (1 - 
5) 2 ||(1 - |A|)|0)|| 2 = l-5(2-5)||(l - |A|M|| 2 . Thus, ||(1 - |A|)|$|| < y^fS. Set S = (2e)V3 to 
conclude \\(U - A)|0)|| < e + 2 4 / 3 e 1 / 3 . (For e < 1/2, S < 1, and for e > 1/2, the bound is trivial.) □ 

Proof of Lemma A. 2. Let us begin by estabiishing some notation. For r 6 R 3 , let R{r) — f ■ 
(X,Y,Z) = ri X + r 2 Y + r 3 Z. Let R{a) = U° s - Ul and R'{b) = Uf - iTi. Let v x = (1,0,0), 

v y = (0,1,0), v z = (0,0,1), v± xy = J=(1,±1,0), v± xz = ^(1,0, ±1), v± yz = ^(0,1, ±1). For 

a E y, z, ±xy, ±xz, ±yz}, let R a = R(v a ), Ra = R(va) and R' a — R f (v a ). For example, R x = X. 
For a vector define the semi-norm ||M||^ = ||M|0)||. 

The proof has two parts. First we consider only the questions a E {v Xl v yi v z } and b E 
{v± xz , v± yz , v± xy }, i.e., question pairs in which Alice is asked to measure along a coordinate axis 
of the Bloch sphere and Bob is asked to measure in a direction between two coordinate axes. In 
particular, we consider three sets of questions: 

1. (a, 6) E {v x ,v z }x{v+ xz ,v- xz }. As | + ^ (S) ^R-^^ + ^ (g) — ^ (g) ) | ^* > = 
2y/2, these questions form a CHSH sub-game. 

2. (a, 6) E {vy,v z }x{v- yz ,v+ yz }. Since (^*\(R y ®R-y Z + Ry®Ry Z + R z ®R-y Z -R z ®R yz )\ij*) = 
—2^/2, these questions form a CHSH sub-game if Eve complements Bob's answers. 

3. (a, 6) E {vy,v x }x{v- xy ,v+ xy }. Since (^*\(-R y ®R- X y+Ry®R X y+R x ®R- X y+R x ®R xy )\^*) = 
2\/2, these questions form a CHSH sub-game if Eve complements Alice's answer to question v y 
and complements Bob's answer to question v xy . 
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By applying Lemma 4.2 to the first CHSH sub-game above, we establish a shared EPR state |^*) 
and characterize Alice's operators R z and R x . By applying Lemma 4.2 to the second and third 
CHSH sub-games above, we come at Alice's R y operator from two directions in the Bloch sphere, in 
order, essentially, to triangulate it. 

In the second part of the proof, we tie in Bob's on- axis reflections. For this part of the proof, 
we use only that (^\R X R x \^*) = (ip*\R z RzW) = -(^*\Ry ® Ry\^*) = 1, i.e., that |^*) is a 
certain stabilizer state. 

Consider the questions (a, o) E {v x ,v z } x {y+ xz , v~ xz }. As these questions form a CHSH sub- 
game, we can apply Lemma 4.2 to obtain a decomposition Ha = C 2 07-/U, W>b = C 2 Hb such that 
|||^) - \r) |^ x )|| = O(v^), R Z = R Z ®1 and ||(^ - = 0(y/e). Also, ^ = R xz 1 

and || {R'- xz — R- xz = 0(y/e), although we will not use this. 

Consider next the questions (a, 6) E {v y , v z } x {v- yz , v+ yz }. Applying Lemma 4.2, we obtain that 
there exists a unitary U E C(Ha) such that UR Z W = R z 1 and IK^ - fJ+it^ 1^)a||^ = 0(y/e). 
Since R z = R z ® 1, it follows that C7 = |0)(0| J7 + |1)(1| U\ for some unitaries U , U\ E £(Ha)- 
Let C/ = C/Jt/i. Thus E/t^ ® = |0)(1| ?7 + |1)(0| Eft. 

Last, consider the questions (a, 6) E {ify,^} x {^-xyj^+ay}- These questions form a CHSH 
sub-game if Eve complements Alice's answer to question v y and complements Bob's answer to 
question v xy . However, we do not apply Lemma 4.2 to this sub-game directly. Instead, modify 
Alice's strategy by replacing R x with R x 1. Since \\(R X — R x 1)a|L = 0(y/e), the correlation 
value of the modified game decreases at most from 2v^2 — 16e to 2\/2 — 0(y/e). Now applying 
Lemma 4.2 to the modified game, we obtain that there is a unitary V such that VR X = R z 1 
and \\(R y + V^R X IV) aW^ = 0(e l ' A ). Since R x = X = |+)(+| - |-)(-|, where |±) = ^=(|0) ± |1)), 

the first equation implies V = |0)(+| Vq + — | Vi for unitaries Vq and Vi. Letting V = VqVi, 
therefore, -V^R X IV = -|+)(-| V - |-)(+| W. 

Combining this with our characterization of Y from the second CHSH sub-game implies: 

Claim A.4. For e < 10 -10 , there is a Hermitian operator S 6 C{T-La) with \\S\\ < \, namely 
S = i(U - U^)/2, such that \\{R y -R y ® S) A \\ i , = 0(e 1 / 4 ). 

Proof. We have 

|||o)(i| ®u + |i)(o| ® c/t + i+x-i ® f + i-x+i ® yt||^ = ( e i/4) _ 

Since |||Y>) - |Y>*)|Y> X )|| = 0(y/e), therefore 

|||0)(1| ®U+ |1)(0| ® C/t + | +)( _| F + |_ )(+ | yt ||^ x) = ( e V4) 

Now substitute = ^(|++) + I )) to obtain 

1/4) = 1 (I++) - I — ))ab{U + U% + \-+) AB (U - C/t + 2 W) 
2 + |+- W-C/ + C/t + 2 y) 

>-^||(C/ + C/t) A ||^ x . 
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This implies our characterization of R y : 
\\R V -R y ® S\\ < \\R y - WX ® 1U\\ + \\W X ® 1U - Y ® S|| 

< p y - f/ f A 1c7|| i/; + 2|||V>) - |</>*)|</> x )|| + H^A ®1U-Y®S\ 



|V>*)IV> X ) 



j?, - WX ® 1C7|| + 2|||V) - |Y>*)|Y> X >|| + 



I. 



h/>*)|</> x > 



= 0(e 1 / 4 ) . □ 
Lemma A. 3 gives a reflection A so \\(R y -R y ® A)a||^ = 0(e 1/12 ). 

In the second part of the proof, we will consider Bob's on-axis reflections. In particular, consider 
the questions (a, b) E {(^, (#2, (v y , v y )}. Note that in the ideal strategy on an EPR state, 
Poo\v x v x = Pn\y x v x = h Pw_\v z v z = Pn\v z v z = \ and Po!\v y v y = Pio\v y v y = i We use these identities to 
characterize R x , R f z and R f y . Observe that, since the provers' strategy is e-structured, 

(i/j\R x ® R' x \i/j) =Poo\v x v x +Pn\v x v x ~Poi\v x v x ~Pio\v x v x > 1 - 4e . 

Claim A. 5. For complex numbers a,/3 with |a|, \(3\ < 1 and \ \{ot + /?) — l| < 5 < \, necessarily 
max{>- l|,|/3- 1|} < y/36. 

We have, using = -^g (|00> + |11)) and successive triangle inequalities, 

\K(o\(r\R' x \m x ) + (ikv x i^io}!^}) - 1| = w\(r\R x ®R' x m\r) - 11 

<2|||^-|^)|V' X )II + KV'I^®^|V')-1| 
= O(Ve) . 

Applying Claim A.5,we_ find max{|(0|(V' >< |-Ri|l)|_^ x ) - 1|, |(l|(^ x |i^|0}|i/> x ) - 1|} = 0(e 1 / 4 ). There- 
fore, max{|||0)|V> x ) - i^|l)|V> x )|| 2 , |||W X > - ^|0)|^ x )|| 2 } = 0(e 1/4 ), and hence, 

\\(r x ® i - R' x ) B \r)\r)\\ 2 = l(\\\m x ) - ^io)iv x )ii 2 + wmr) - j^i w x >|| 2 ) = o(e 1/4 ) . 

It follows that || (R x — R x ® — 0(e 1 ^ 8 ). For R' z , a similar argument implies \\(R f z — R z <8> 1)b\\^ — 

0(eV8). 

Finally, for R' y , we have (ip\R y <£> R' y \ip) < — 1 + 4e, and therefore 

\(r\w x \(Ry ® a) a ® J R;ir>i^ x > + 1| < 2inr)i^ x ) - i^)ii + ii(^ ® a - ^ui^ 

The left-hand side of this inequality is ||(a + /3) — l|, where a = i(0\(ip x \A ® R y \l)\ip x ) and 
p = -i(l|(^ x |A ® R y \0)\ip x ). By Claim A.5, max{|a - 1|, |/3 - 1|} = 0(e 1 / 24 ). Therefore also 
max{p;|0)|^ x ) - i|l)A A |^ x )|| 2 , \\R' y \l)\^ x ) + i|0)A A |^ x )|| 2 } = 0(e 1 / 24 ). This bound nicely char- 
acterizes R'y. Expanding \tp*), it gives 

\\R' y - (R y ® 1) B ® A A ||^ )|V;X) < ^(p;|0) - i|l)A A ||^ x + + i\0)A A \\^ x ) = 0{e 1 '^) . 

Using the same inequality, we can also argue: 
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Claim A. 6. There is a HermitianS' with\\S'\\ < 1, such that \\(R!y - Ry ® S')b\\^*^ x) = C^e 1 / 48 ). 

Proof. Expand R' y = |0)(0| ® A + |0)(1| ® S + |1)(0| ® fit + |1)(1| ® C, where i,B,CG each 
have norm at most one. Let S" = i(B — B^)/2. 

We are given max{||A|| J x + ||(4 - zA A )||J x , ||C|| J x + + iA A )||J x } = Ofe 1 ^). Therefore, 
||(5 + 5t) B ||^ x < ||B B + iA A ||^ x + ||S^-iA A ||^ x = 0(eV48). S i nce ^ - R y ® S' = |0)(0| ® A + 
|1)(1| ® C + i/^ ® (S + fit), it follows that \\R' y -R y ® S'|L,_ X) = C^e 1 / 4 *). □ 

As before we did before on Alice's side, we now apply a Markov inequality to approximate S' by a 
certain reflection. Indeed, Lemma A. 3 gives a reflection A' so \\(R y — R y ® A / ) j b||,^ :4c ^^ x , = (^(e 1 / 144 ). 
Therefore, too, 

||1 - A A ® A^l^x = \\(R y ® 1) B ® A A - ® AOslli^j^x) = Ote 1 / 144 ) . 
Therefore |A A ® A' b \^j x ) = 1 - - A A ® A' B ||J X > 1 - 0(e 1 ' 72 ). □ 
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